Live data from Hacker News

Indian Government Breached, Massive Amount of Critical Vulnerabilities

johnjhacking.com

51–60 of 74 posts

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#51

This smells a bit off: why is there no detail whatsoever on what exactly they breached? The "Indian Government" (central, state, other?) is a sprawling octopus that employs on the order of 50 million people, and there's a world of difference between breaching the public site of the Department of Fertilizers ( https://fert.nic.in/ ) vs getting into the internal systems of the Ministry of External Affairs. The only clu…

John Jackson (johnjhacking) is not jacksonhhax, though they're both part of the same group.

For context, John's a vet who's employed in the field. And beyond that, he's published other sound security research in the past, e.g. https://johnjhacking.com/blog/cve-2020-28360/ (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2836..., which links https://github.com/frenchbread/private-ip)

As for the attribution chain to sakurasamurai.org, reference the following:

• twitter.com/johnjhacking refers users to

• twitter.com/sakurasamuraii, which links

• sakurasamurai.org in a pinned tweet.

Source: I know John personally.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#52
post #32

Everyone seems to assume it is the central government. No one has remarked on this, the following somewhat obvious. One of the screenshots has a heading in Malayalam, saying "Bill Vivarangal" - "Bill details" [1]. Was it some government of Kerala service which was breached? Or is it one of several governments? Or was it only the central government with Malayalam as the language set for the interface? If it was an Ind…

https://sakurasamurai.org is newly added domain (suspicious). In India there are some motivated groups try to blame central government for every action. I believe this is a new group and trying the same thing.

The domain is fine. My reasoning is that I know John (johnjhacking), have worked with him, have at times educated him, have on more occasions learned from him, and lastly, the attribution chain is

* twitter.com/johnjhacking refers users to

* twitter.com/sakurasamuraii, which links

* sakurasamurai.org

It's not a random group trying to defame a government. It's a known security researcher with a sterling rep.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#53
post #47

Earlier quoted context omitted.

> 10e6 Under scientific notation, you should strongly prefer to write 1e7. 10e6 is just begging for people to interpret it as 10⁶ rather than 10×10⁶ (10⁷).

But that's the definition, and every calculator's "engineering" mode shows it exactly like that, too. And usually you learn in middle school how to interpret that. Here’s a photo with the calculator I used in middle school, showing exactly the specified number: https://i.k8r.eu/qOUpgg.png

Curious. I don’t have a traditional calculator to hand, but tools like Rust, Python and Wolfram|Alpha are all turning 10e50 into 1e51.

https://en.wikipedia.org/wiki/Scientific_notation#Normalized... agrees with my memory that in normalised form the coefficient should be at least one and less than ten.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#54
post #47

Earlier quoted context omitted.

But that's the definition, and every calculator's "engineering" mode shows it exactly like that, too. And usually you learn in middle school how to interpret that. Here’s a photo with the calculator I used in middle school, showing exactly the specified number: https://i.k8r.eu/qOUpgg.png

Curious. I don’t have a traditional calculator to hand, but tools like Rust, Python and Wolfram|Alpha are all turning 10e50 into 1e51. https://en.wikipedia.org/wiki/Scientific_notation#Normalized... agrees with my memory that in normalised form the coefficient should be at least one and less than ten.

MeE isn't M^E, it's defined as M * 10^E.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#55

Earlier quoted context omitted.

Curious. I don’t have a traditional calculator to hand, but tools like Rust, Python and Wolfram|Alpha are all turning 10e50 into 1e51. https://en.wikipedia.org/wiki/Scientific_notation#Normalized... agrees with my memory that in normalised form the coefficient should be at least one and less than ten.

MeE isn't M^E, it's defined as M * 10^E.

And that’s what I was talking about from the start—10e6 is 10×10⁶, which is in normalised form 1×10⁷ or 1e7.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#56
post #32

Everyone seems to assume it is the central government. No one has remarked on this, the following somewhat obvious. One of the screenshots has a heading in Malayalam, saying "Bill Vivarangal" - "Bill details" [1]. Was it some government of Kerala service which was breached? Or is it one of several governments? Or was it only the central government with Malayalam as the language set for the interface? If it was an Ind…

https://sakurasamurai.org is newly added domain (suspicious). In India there are some motivated groups try to blame central government for every action. I believe this is a new group and trying the same thing.

> "some motivated groups try to blame central government for every action"

Nice try there bro. But unfortunately newly added domain doesnt disprove anything mentioned in the article.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#57
post #41
post #18

Earlier quoted context omitted.

> Why did they published anything about the vulnerabilities before they were absolutely sure all of those has been mitigated? Because various entities tried to exploit that to defer any publicaton, which lead to things never getting fixed. An entity may not want to fix things, but at some point their users / constituents have a right to know so they can take their own protective measures.

> Because various entities tried to exploit that to defer any publicaton, which lead to things never getting fixed. Also understandable. > [...] so they can take their own protective measures. Little can the ordinary citizen do whose data is at risk of exploitation. All responsibility lies on the government because the citizens do not have any other choice, as it seems to me. What protective measure can someone take…

> What protective measure can someone take who is vulnerable?

Like deleting your sensitive documents that you have uploaded already. Removing contact information and other personal details.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#58
post #47

Earlier quoted context omitted.

But that's the definition, and every calculator's "engineering" mode shows it exactly like that, too. And usually you learn in middle school how to interpret that. Here’s a photo with the calculator I used in middle school, showing exactly the specified number: https://i.k8r.eu/qOUpgg.png

Curious. I don’t have a traditional calculator to hand, but tools like Rust, Python and Wolfram|Alpha are all turning 10e50 into 1e51. https://en.wikipedia.org/wiki/Scientific_notation#Normalized... agrees with my memory that in normalised form the coefficient should be at least one and less than ten.

And the paragraph below the one you linked... https://en.wikipedia.org/wiki/Scientific_notation#Engineerin... is directly showing exactly the mode I'm using :)

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#59

This smells a bit off: why is there no detail whatsoever on what exactly they breached? The "Indian Government" (central, state, other?) is a sprawling octopus that employs on the order of 50 million people, and there's a world of difference between breaching the public site of the Department of Fertilizers ( https://fert.nic.in/ ) vs getting into the internal systems of the Ministry of External Affairs. The only clu…

> Update: the leader of the "Sakura Samurai" appears to be 15 years old, which explains a lot.

What does it explain? Anyone who is not familiar with the branches of the Indian government could have omitted specific details of which departments were hacked.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#60
post #29

If these guys were Indian pretty sure they would be facing jail time for exposing such vulnerabilities (1) (1) https://www.livemint.com/Opinion/S6Ep52qB9PK1DRLFUbUDBK/The-...

Well. Section 47 is a real delight, a diabolical inversion of the principle of locus standi. Increasingly, there are agencies and laws which say that "you cannot take us to court". As though writing it makes it somehow legal. Reminds me of calvinball.

Sovereign Immunity means you can't sue the government unless given permission by a statute anyway.
Post reply on HN