Also, this sort of event should result in some hackers being found and jailed for life as well as their families being bankrupted permanently. Or, if they are being protected by their government, this should be considered an act of war and an appropriate military response should be delivered.
No one thinks bills of attainder are a good idea.
The whole country's real estate market was paralyzed for about a month. It took couple of months to restore everything from backups and paper agenda and resume normal operation of the land register office.
It was the largest cyber attack in Slovakia's history. The authorities to this day haven't provided any information on who might be behind it. The investigation is still ongoing. Several government figures including the PM were however very eager to immediately point on Ukraine, without any sort of proof.
At this point he is just subverting EU on putin's whims. Stealing half of EU funds evidently wasn't enough for him, plus he can see some protection in the east, west has only future jail for him. If one country should be kicked out right now, it should be this one.
"1T+ in assets are frozen as Slovakia's Land Registry faces ransomware attack" <https://spectator.sme.sk/politics-and-society/c/news-digest-...> (9 Jan 2025) HN discussion (1 comment): <https://news.ycombinator.com/item?id=42650343>
"Ransomware Attack Paralyzes Slovakian Land Registry, Souring Slovakia-Ukraine Relations" <https://dailysecurityreview.com/security-spotlight/slovakian...> (January 14, 2025)
"Slovakia Hit by Historic Cyber-Attack on Land Registry " <https://www.infosecurity-magazine.com/news/slovakia-hit-by-l...> (10 January 2025)
Apparently tied to Ukraine in this case.
Lord no! That accusation doesn't pass the sniff test.
Try looking further east for the real culprits.
If you've specific information clearing or establishing the link, post it. I agree that hasty accusations are risky. The main point I was looking to establish was that the source wasn't indicated as Algerian, as with the Romanian incident.
That they throw guilt on Ukraine doesn't mean anything at all since its all politics to shift blame anywhere but their own incompetency, especially without specific proofs provided (for which there aren't any even 18 months after the crime).
<https://en.wikipedia.org/wiki/Robert_Fico>
Not to be confused with, say, Fair, Isaac, & Co., a credit-scoring company, or its eponymous FICO score (<https://en.wikipedia.org/wiki/FICO> and <https://en.wikipedia.org/wiki/FICO_score> respectively), an abbreviation for a FInancing COrporation (<https://en.wikipedia.org/wiki/Financing_Corporation>), or even a song by Cliipse and Stove God Cooks (<https://en.wikipedia.org/wiki/F.I.C.O.>).
It wasn't immediately clear to me what (or who) "fico" (lowercased) referenced. Make your reader's job easier and be clear in what you're stating. Slovakian politicians of any standing may be less widely recognised internationally than you expect.
And yes, Wikipedia notes Mr. Fico's Kremlin-friendliness, which would cast doubts on his credibility in such matters.
Again: I've no particular reason to believe the account, hedged my own belief, and don't see much evidence for (or against) the accusation, though an early naked attribution of responsibility without any particular evidence isn't particularly convincing. Again my first reaction to the accusation was doubt, and I continue to harbour same.
So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.
/joking, i'm sure this is not a happy time for whoever is trying to rebuild everything
> spinning up a new shard takes a quarter
Both can be true
When I was responsible for backups we kept the tape cartridges in a fire safe in a different building. We took a full backup weekly and moved the tape from the robot to the firesafe as soon as the backup was complete. Only the daily incremental backups stayed in the robot for more than a day.
You would need to understand first how they gained access and verify that they can’t do the same again. That in itself could take days if not weeks. Then of course they might have found new vulnerabilities while they were in, so you would need to worry about that too.
Yes, even hundreds of them sometimes.
The most time consuming part of recovering from an attack is validating everything. It takes more than a few hours to validate the infra that stays put isn’t compromised, the IaC code itself isn’t compromised, deploy the infra, bring a copy of the offline backup of your data (your IaC can’t drive to another site and bring the backups, then make a copy, unless tou are really sure you removed any trace of compromise), validate that the backup is sound, then restore it.
In some cases the infrastructure part is the least time consuming. Some platforms are straight forward enough that even manual deployment is fast. But after a hack you can’t trust anything so you need to do the slow validation that takes longer than your projected “hours”.
> In some cases the infrastructure part is the least time consuming. Some platforms are straight forward enough that even manual deployment is fast. But after a hack you can’t trust anything so you need to do the slow validation that takes longer than your projected “hours”.
Your IaC is supposed to be on those offline backups too, and should be able to do everything from clean hardware.
The most time consuming part is to identify what caused the compromise. After that, you can put everything back online and then at the same time start to analyse who did it/what they did and so on. If the root cause for the breach is identified, you also know the time most likely and can trust the offline IaC backup.
In his thesis, this is the reason capitalism cannot work well in Latin America and other nations around the world. He says that registered land ownership is the foundation of capitalism. This is how one can borrow money against your land and invest it to make more capital. Very common for example with farmers in N. America to borrow against their farm, for machines, seeds and fertilizer.
(I am not an economist)
De Soto is talking about why it "cannot" get started in a place without government controlled land registry.
"Cannot work well" and "cannot get started" are two different things. The whole of Latin America apart from Cuba is capitalist, for better or worse, regardless of how bad those countries keep their books.
And yes I can see that we are at the end of an era. This may be more the end of the U.S. empire than the elimination of capitalism, but for sure a new 'ism" is going to be required soon. What that is will be interesting to see. It would be nice to see someone with imagination come along instead the bipolar options we are handed today.
De Soto describes the exact opposite situation. Latin America inherited Napoleonic property law, which only recognized property ownership when formally registered, which required quite alot of red tape. It was impossible to transfer ownership without registration. Moreover, any defect in prior registration meant the lawful owner might be the heirs of someone generations ago. Most property "owned" by the peasantry usually had defective and incurable title, having changed hands in informal private agreements, which meant banks wouldn't accept it to secure a loan. This meant only the aristocracy could leverage the financial system, because they were accustomed to following all the formalities. What piece of real property someone thought they owned, even if occupied for generations, was often in the eyes of the law owned by some aristocratic family or the state.
He contrasted that system with the American common law system, where title could be legally transfered entirely privately. Disputes are handled by courts which look to the timing and substance of transfers. Moreover, adverse possession meant that after a number of years (well within one person's lifespan) nobody could come along and claim title because of a defective transfer (even if in principle they had a better claim originally), securing title in whomever held it, even if it had been transferred without even following the much looser requirements under the common law. A bank would issue a loan so long as you could prove you held an unchallenged title for a sufficient number of years. ("Title" was whatever piece of paper handed you by the previous possessors; no government stamp or recordation required.)
Registration systems in the US are a recent occurrence, and they overlay the traditional common law rules.
A gross generalization, but Napoleonic civil law systems emphasize formal transactions centrally administered by the state, while the common law emphasizes looking to the substance of private transactions, and usually only when a dispute arises (otherwise you just presume they're valid). Broadly speaking, De Soto argued the latter tended to favor the common man, because it was much less rigid.
De Soto also pointed out that US Federal Land Grants also did a decent job at distributing land among the people, unlike Latin America where mostly only the aristocracy held land under a good title.
There appears to be a push to control open source software, in the guise of protecting children via age control.
With OSS, anybody can tweak the code on his device to pass the control, so the idea would be to only allow certified software. Which is expensive, and out of reach of most open source projects. Enter big, reliable companies that can afford the ticket for the certification of horrendous piles of slop.
see this recent HN post about it, I find it resonates, so to speak, with what you explain :
ADDED: We also had a bunch of easements and cooperative maintenance agreements that were only partially documented in the deed and mostly done via a handshake. So we got that all squared away in the expensive binder from the lawyer.
The United States on the other hand has a massive title insurance industry, which wouldn't exist if this system was implemented. So you can make random handshake agreements all you'd like and sue over it.
[1] https://www.elra.eu/the-principles-underlying-the-land-regis...
Sort of. The registration is what provides opposability against third parties. But between buyer and seller, the transfer of ownership happens by the contract itself. You'll have a harder time against creditors of the seller placing liens on the property, or other people claiming to be owners (e.g. if they bought the foreclosed property); how hard a time depends on the country.
And there may be still be encumbrances/claims to the property that are not subjection to registration like adverse possession or rental agreements that can be asserted against the buyer and for which the buyer's only option is to sue to the seller.
(And obviously has some doc to prove it)
"i paid for 30 acres here at $xx rate, and here is the mortgage docs from the bank dated March 19th that I signed, plus their valuation of the property and what went into it"
[1] https://community.apryse.com/t/jbig2-compression-issue/1814
[2] https://en.wikipedia.org/wiki/JBIG2#Character_substitution_e...
"Hold up in court" as in was it duly executed and filed by a certain date, regardless of the time and extra management required for the bank's performance? Yes, why not.
"Hold up in court" against someone claiming it was an unauthorized transfer? Even without the bug, that can be contested in many straightforward ways!
But unless there is a specific legal claim that hinges on the bug being significant, it's pretty irrelevant "in court". I knew about this precisely because the transfer failed to go through due to redundancy - one digit in account numbers is generally a check digit, plus account titles and whatnot.
In general you can always challenge the validity of scanned documents, regardless of known software bugs or not! Just like you can always challenge that a paper document is a forgery. You need a specific argument and some evidence though!
But sure, IFF you had an instance where an amount transferred was wrong and their various settlement/accounting tallies didn't catch it, and the bank refused to look into and fix it on their own, and you had a reason to believe they used a paper form for that, then yes you would have a good argument that could be used in court!
When you buy property you get a deed for the land, but the details of a property can change after that. The deed also doesn't contain ownership, it just says what is on the land. It's common for land to have multiple owners (1/32 is not unheard of) due to inheritance.
I'm building a house, the land deed just has the land plot as we bought it, until the house is 100% finished (and registered) we will not get an updated deed, although the digital system has newer data (you need to register the construction progress).
Just recently I've seen a 30 y.o. deed on some commercial property. Despite it was valid and predated the digital era, it had almost nothing common with the things on the ground.
Property that isn't registered can remain unregistered but must be registered before it is sold.
It's literally not a requirement to have it all online. And the cost of developers, plus coding + security updates + platform costs, really just means you replace a few assistants which would process requests by hand, with all that.
Except? It's a lot harder to hack a person to delete all the files in the office, from 10k km away, than via a computer.
So many things simply don't need to be online. So many things simply are better archived by other means. So many things are safer, more secure, and the backup processes (microfiche, etc) are well understood and just work.
If we start thinking along the lines of technology has risk and we shouldn't use it, we should go back all the way to the discovery of fire as we all know fire can cause a lot of damage if in the wrong hands.
In as software is not secure, and can not be made secure, using it for important records storage makes zero sense, unless you a) have full backups offline in physical, non-digital, read only medium or b) just don't do it online, at all.
And my point is, it's not worth the convenience.
Think about it. To destroy the public archives, of which there is typically more than one, you must travel to said location, breach it with weapons and other means, and destroy it. Or, you can sit in your parent's basement in your pajama's, and hack and destroy.
There is not even remotely the same risk profile.
And if you think something is "good" because 'the world thinks it is good', then I have to ask you why you're validating something via popularity. You know what else was popular? Fossil fuels. Smoking. Using uranium in makeup for women. Something being accepted, and being fun or convenient, doesn't make it correct, sensible, or right.
So please describe the horrible and incredible "gigantic convenience". Because I lived before the internet, and now after, and yes it is convenient.
But it certainly isn't a 'gigantic' one, nor is it sensible compared to the insane attack surface and risk.
And of course everything didn't work perfectly, it did however work "perfectly fine", which means "very well" or "good enough". Meanwhile, adding in network connectivity to anything vital these days is just insanely dumb.
No software is secure, and will never ever be secure. Ever. Anyone who thinks that software can be made secure, is 100% wrong, period. My point is that the advantages aren't worth the disadvantages.
And as a third option we can have efficient digital systems that aren't plugged into the Internet. (Presumably the Internet could have a copy that's regularly updated.)
I've seen 'competent' backup solutions which had backup rotations that expired older content. And I've read post-incident responses where hackers slowly corrupted older records. And (via reading corporate wikis and docs), determined how long they had to wait, for backups to become tainted.
But I agree. True competent backup methods, including periodic backup restoration tests and other methods, can ensure a degree of protection. Still, one can end up with months of "bad backups" due to a hacker interceding in the process or corrupting records slowly, thus invalidating more recent backup sets post-hack. While this didn't happen with Equifax, the hackers were in there for 8 months slowly exfiling information.
So you can have a load of backups with questionable integrity.
Really, what I'm comparing here is indelible backups vs not. It could be holographic, write only storage for all I care. It's just that "paper" backups, which move to microfiche, have a century long history of how to deal with it. How to ensure they're good. How to keep duplicates, resolve security, and all that.
Meanwhile, most people dealing with the software side simple think "Oh, we can make this situation secure. We can make software secure."
This thought process is entirely wrong. Software is never secure. If you use software + a database or other store for data, it's not secure. And so, placing it online is just plain stupid.
Of course, you speak to other options. No external network connection, for example. And this is all well and good! And it significantly reduces the attack vector.
But of course, and lots of high security environments do this, you then have to ban staff from bringing in all phones, computers, and other devices. I read a post-action report where people's phones were hacked, and basically acted as a 2G modem (at the time) into wifi on an isolated network of a nuclear power plant. And due to the thought process of "We're 100% air gapped, who cares!", the hack was apparently an easy one.
But really, the difference is... how many people can attack your citadel.
The internet means billions. No network connection means hundreds.
It's just that simple. And I think you agree, mostly.
Suddenly your entire argument shifted in my head and I fully agree.
Might be something there I can learn about myself then :D
The real danger is that we’ll be so careless we’ll discard other enduring ways of doing things before we smarten up to their particular benefits.
My hope is that disciplined people still have an intuition for this, even among the digitally steeped. Sysadmin/ops types tend to a culture of diversifying backup location and even media type. Maybe that can reach back to human legible hard copy.
A sophisticated genius hacker in a different country can’t touch your paper records, but an absolute moron with a bic lighter can destroy records just as effectively. Hell, an irresponsible clerk can do an incredible amount of damage just by misfiling things.
Duplication literally doubles costs in the physical world, and has the downside of being very hard to keep in sync. A bank keeping paper ledgers would be absolutely fucked if they had to switch to a backup ledger that was more than a few hours old.
On net, I believe that digitalized documents are a net improvement.
Put some desktop-size tape robots in several government building closets, and task someone with switching tapes weekly, and you can achieve more reliability than multiple huge paper archives.
So they rebuilt it first from first hand proof, then by testimonies, with a period of counter claims available IIRC. For sure there were some false claims, but given the magnitude of the disaster, this is the best solution within that context.
If the you need to know if the fence is on your property or the neighbor’s, a title or deed won’t help you find that line.
So if the official survey is lost and you need to know where the land you own is, you will need a survey.
A survey is little more than marching out into the field and putting at the location where you believe the boundaries to be based on your review of the legal description.
Of course that’s not the end of the discussion as to boundaries for reasons like adverse possession or busted titles but on his own a surveyor is going to tell you basically nothing.
A great-great grandfather of mine was mayor of a town through which the front passed twice during WWI. All that survived were basements. Your father's account more or less describes the process by which the land was reparceled.
In a similar vein, I was once curious how you would prove your identity if ALL of your relevant documents (passport, driver's license, birth certificate etc) were lost in some kind of cataclysm e.g. a house fire pre-digital etc
Turns out there is actually a mechanism for this:
- get multiple people to sign sworn affidavits that you are who you say you are
- that begins the "paper trail" of evidence that allows you to start getting the rest of the document chain
- you rebuild from there.
If you're married, there is already a similar process for when a spouse takes the last name of the other spouse. The marriage certificate is the first step and then it goes from there for driver's license, passport, credit cards and so on.
Oddly enough, if you legally change your name, they will send you a new one regardless of the limit.
It is very unlikely that you will be asked, even by a prospective employer, for your actual card, because let's face it: it doesn't even have a photo, or anything but that unique number on it. Anyone trying to authenticate your number should be satisfied if you can give them the correct number.
And just for review: SSNs are not a "national ID" and you're typically not required to divulge it to private parties, and they can make up some other unique ID for you in their database. It's usually just a shortcut for them to do a background or credit check on you. And that's not something for which they would need your physical card.
That being said, I've replaced my card about 3 times now, and it was comparatively difficult this time around. The first time, I did it all through the mail (the process of building up from no ID to get birth certificate from out-of-state, to the SSA card, to the in-state driver license.) and the second time it arrived by mail, no hassle.
But this time around, even though I applied online, I was directed to make an appointment at the field office and physically walk in there, to prove my humanity. I had never been to an SSA Field Office in my life! The experience was very chill, and there were a dozen windows serving people, while about 4 of us waited in the lobby, and I was in-and-out half an hour early. The civil servant was a lady in good spirits who was a military veteran. Big props to them!
In my state, it's one of the allowed document types for proof of social security number, required to get a real ID drivers license.
https://www.mass.gov/doc/ma-real-id-documents-checklist/down...
That's not what they are, but that's what they've defacto become. I hate it.
Except for certain industries where the government has a direct interest (banking, healthcare, real estate), I don't think anyone has asked for my SSN in at least a decade. It's not like the old days when you'd fork over your SSN to rent videos at Blockbuster.
That's still a massive dependance on "ID" for SS...? Blockbuster tho.. phew it's been a while.
I'm curious when this happened. The phrase "but this time around" makes it sound fairly recent. However, my wife had this very procedure required back in the 1990's.
She also had the same experience as you: Very friendly civil servants eager to help, and things were cleared up quickly once she understood the process.
Or did a joke about overbearing mother in laws just go right over my head.
It is definitely a good idea to plan in advance and set up a recovery contact: https://support.apple.com/en-us/102641
And that link is to recovery contacts, not codes. If you’re willing to trust one person you can get back into your Apple account after a disaster.
"Oh volcano exploded, his home is under 5 ft of ash."
"Gotcha, mail him the copy"
What you need is "pyroclastic event" insurance to cover you for ash and lahar.
/ It cost something like $15/year when I lived in Seattle.
// The macOS spell checker doesn't know "lahar."
- get insurance to cover you for X
- get hit by X
- realise you actually got hit by Y after reading the policy small print (or you really did get hit by X, but your policy only covers you for Y)
Getting something like Volcano Insurance requires some specific foresight, I would be slapping myself on the back if my house was covered in volcanic ash right up to the point when I got on the phone to my insurance company to make a claim.I got my first passport at a formative period of my life (international travel does that). I looked nothing like the photo within aa year. It served as a passport until it expired but only created skeptisism as a photo ID.
I don't know how to drive, so do not possess a driver's licence. I am in a 35+ year relationship, but unmarried.
The only purchase I have made on finance was a bed that I immediately paid off because the the only reason I did it was to establish a record. This was surprisingly difficult to do because they were reluctant to let me have the bed on finance because I had no credit record.
I finally had to renew my passport when I bought a house. It was the only way I could meet the id requirements.
Prior to that I was leveraging non-photo id that could only be acquired with photo-id. It seen that will be accepted in lieu in many instances and allows you to get more similar forms of non-photo ID. All you need to get started is to find a staff member fed up with the ridiculous rules enough to click the checkbox to say that they saw a photo ID. It helps that many of the staff in these positions are more aware of security theater than the general public.
Being a land owner means a lot of those days are peassed, I can't really prove I am the person who is recorded as owning the land, but mostly organisatipns are happy that I am claiming to be someone they know exists.
Linkedin has stopped asking. I'm not sure if that means they think I am a lost cause or that anyone not on their books by now doesn't actually exist.
Everytime I get stuck with some kind of circular bureaucracy I shout "it's Banana Joe all over again!" and no one understands.
And now I also know that he has a law degree, has several registered patents, and was a certified airline pilot. Pretty impressive.
Of course, if you fall into a crack that is beyond their reach you will almost certainly have a more difficult time. For a variety of historical reasons, there has been relatively little reliable documentation of American citizenship so the system adapted to that reality.
They even show how they did historically which is super interesting!
Unfortunately changing the borders is super expensive and time consuming though so I didn’t do anything.
So all is not lost if the registry goes up in flames.
You know, it's not like people would come and steal your land overnight because you can't provide proof of ownership.
Plus having most of your net worth locked up in something no sane person would consider buying off you because you can't prove you own it is ... suboptimal
That's... a curious thing to have in the body of laws. What's its purpose and who does it serve?
The advantages are you can see who owns the land, there's no argument in 20 years time when someone puts a competing claim.
There's an entire industry in the US dedicated to working around the problems that buyers have https://www.alta.org/
If you buy land, then build a house, then someone comes along from 1932 saying "actually that land is mine", you are screwed.
And as for being screwed, that’s why real estate transactions have title insurance - to cover damages from incorrect titles.
Even if the digital records were completely lost, they still have the paper ones.
> being unable to prove land ownership
People know who owns what, there are also paper contracts of ownership which are more authoritative than the digital records.
The last thing any government will want to deal with is massive irretrievable data loss.
accidental communism
If the hacker was targeting the erasure of a particular recent transaction, they may well have succeeded. And by deleting numerous others, they have plausible deniability in the subsequent dispute over the property. If you just wipe a record that is related to you, and the manipulation is discovered (which it will be, one way or another), you are part of a narrow circle of suspects.
Also, you still have paper documents, kept by parties to transaction, right?
All you need is an append only tape or even a printer.
Interestingly in the Bangladesh Central Bank hack they used a printer to print out any transactions, but the intruders disabled it or it was just malfunctioning because it's a printer.
But I doubt the Romanians actually had such a system.
I had a copy of our code on media in my desk labeled “promotion” and updated it every month. In retrospect someone going through my desk would have assumed blackmail material and been disappointed to find only code.
The digital copy is just that; a digital copy.
The hacker would have to destroy the database and all backups, and also burn down the building holding the registry.
People would get their buddy to agree the land was theirs so not a perfect system, but some families were made more whole.
The intent of abolishing private property would presumably be the latter.
I've seen it personally fail miserably and destroy entire nation's spirit for generations to come (on top of other things destroyed for good).
Needless to say, capitalism with its harshness to laziness and carrot on the stick for hard workers got within 2 generations massively ahead, to the point where Gorbachev didn't believe it wasn't Potemkin village setup when visiting some random grocery store in western Germany and seeing the vast amount of produce and quality available to everybody, on level even he personally could only dream of back home.
It did help the West, and especially the UK, to get as immigrants very high good plumbers and handy men. The rest of us went into STEM and are now working for FAANGS.
> Sources told Risky Business that the hacker entered using valid credentials
This is social engineering or corruption.
If stored properly.
So are digital copies, though. If stored properly.
And both storage can be broken, needing reconstruction.
If I were to give you a 70y old book in English vs some 70y tape with data on - which one is easier to read?
If the medium isn't destroyed, it is directly readable if it's a book, but not necessarily so in digital because hardware and software is needed - just taking care of the original medium isn't enough in digital over centuries.
But it's more difficult to imagine that 1000 years from now someone will be able to read from a PCI-E NVME drive if the specs get lost along the way (ignoring for a moment that flash storage most likely won't retain data that long).
Totally agree on accessing NVME example.
mirror that DB onto a server on the other side of the country, or continent, etc.
Moving from a paper registry at each county clerk (in the US) was a part of the 2008 financial meltdown.
Specifically:
- government gives IT/data contracts to cronies
- cronies don't actually do any real security work to protect the data
- things like this happen
Corruption and oppression are signaling and coordination problems. The illegitimate sovereign is exploiting informational assymmetry: they know your neighbors are just as angry as you, they know it because all the walls have ears.
They need to prevent you and your neighbors all knowing it at the same time. Your best play is to find some signal, something difficult to censure, hard for the goons to pick out in a crowd but legible to your neighbors. If you all knew that the first guy to shove back when the cop shoves you is going to be followed by a swarm of guys? Very easy to find the first guy in that case.
This is why shit like extremely high gas prices scares the shit out of illegitimate sovereigns: they're the ones posting pure data about why everyone should be that angry right now.
The amount of times my SSN and correlated info has been leaked and I've been offered a free year or credit monitoring is depressing.
If they are clearly misusing a system (SSN) never designed nor intended that way. And continue to do so even after being shown the facts.
> Sources told Risky Business that the hacker entered using valid credentials
Like whenever someone gets caught in a compromising situation they say they "were hacked", as if saying that means anything.
It's even more funny on Reddit when you can see the person who is blaming cronies in his Romania but has posts of him doing some blue-collar work in the Midwest.
A close relative, government employee, was in charge of building a new application. They have nobody in that entire organization of several thousands people that know how to write specifications for an IT application, nobody that knows how to design, test and deploy it. This is because some government employees have decent salaries, but in IT the private sector is paying a lot more, so almost anyone remotely competent is going to the private sector. So in this case an organization of non-IT people had to deal with the contract and all the associated problems - there is no need to guess, it did not go well. That kind of project could have been done properly with ~ 10% of the budget in the same timeline.
I have a friend that worked as a developer in such a government IT project. The project cost was ~ 5-10 times what was worth, a chain of sub-contractors did the work, less than ten competent people doing the project, charged by the bid winner for over 100 people and actual staff was around 70 at most, for a short period of time.
Both projects above are in Romania. Lack of competent people in the projects, especially in decision roles, was the main problem.
In this case I expect an underpaid employee, and at most an incompetent nephew of someone. They had no reason to have an .authorized_keys file in the webroot of the website, and yet they did.
If you want to know what "dedicated contracts" look like in practice they are overly specific requirements than can only match a single business. The best example that comes to mind was when one county needed to buy busses (or vans) and the maximum length admitted was bellow the most common options, but as luck would have it a nephew of a cousing of someone with decision power (or something like that) just so happened to be the one importing cars that precisely matched the specs.
Here is one I learned recently - govt started issuing birth certificates online. Hopefully Less corruption, right? Officials made deliberate spelling mistakes in names etc, because you have to go in person for corrections. In person means bribe, which means back to same situation as before (almost)
ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.
After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.
ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.
According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.
The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.
The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.
This proclamation, coming from a governmental organization, makes me afraid they are doomed. Effectively they are saying they are fixing the mistake by repeating it.
What they should do is admit fault. Freeze the system. Get independent expert help.
Best wishes, recent Romanian land buyers and sellers
Edit: thank you @cbg0 for giving us this update
At the same time they are working with authorities.
Not everything needs an external consultant.
The dumb thing was the bank was two blocks from the data center and less than eight (six?) from the office so catastrophic events might have hit both or all three. The owner kept a second copy at his house, and that was the only geographically separated copy.
One of the lessons (and subsequent data integrition / continuity of business practices) learned from the 9/11 attacks in New York City, and destruction of both primary and secondary data stores of multiple entities (as well as several emergency-response agencies at various government levels from city to federal) was that essential data and operational roles need to be redundant across very widely-separated locations.
E.g.: from "Discussion note prepared by staffs of the Federal Reserve, the New York State Banking Department, the Office of the Comptroller of the Currency, and the Securities and Exchange Commission, for discussion at a meeting on February 26, 2002 at the Federal Reserve Bank of New York":
[I]t was clear that business continuity planning had not fully taken into account the potential for wide-area disasters and for major loss or inaccessibility of critical staff. Contingency planning at many institutions generally focused on problems with a single building or system. Some firms arranged for their backup facilities to be in nearby buildings on the assumption that, for example, a fire might incapacitate or destroy a single facility. Very few planned for an emergency disrupting an entire business district, city, or region. As a result, some firms lost access to both their primary and backup facilities in the aftermath of the September 11 events, severely disrupting their operations.
"Summary of "Lessons Learned" from Events of September 11 and Implications for Business Continuity" February 13, 2002" <https://www.sec.gov/divisions/marketreg/lessonslearned.htm>
Geographic distances were rarely considered prior to 9/11. Most companies were comfortable replicating data intercampus or to a facility within a few miles of a primary data center. A few firms, such as Nasdaq, actually replicated data out of state.
"9/11: Top lessons learned for disaster recovery" (Sep 9, 2011) <https://www.computerworld.com/article/1545389/9-11-top-lesso...>
Also: "Hard-Earned Disaster Recovery Lessons From 9/11 and other disasters" (2025) <https://backupcentral.com/hard-earned-disaster-recovery-less...>
Terrorist attacks, natural disasters, widespread power and other failures, etc., can all have impacts across many kilometres, possibly many hundreds. Redundancy equates to survivability here.
More broadly, information and data services are fundamentally about risk management and disaster response, as realised during 9/11 (as well as multiple earlier and subsequent incidents) in ways which weren't fully realised at the turn of the millennium. Or even today in some organisations.
Make backups. Test backups. Practice switchovers between primary and secondary (or multiple redundant) operations. And keep those resources and facilities widely separated.
Pol Pots Khemer Rouge come to mind. The "abandon free trade lets go full bio" of the Lebensraum was in the same spirit.
Arguing against all societal complexity is asking for a genocide, how unpersonal and not hate-driven it seems on the surface level.
Your sentiment makes sense on a "We deserve a optimal ratio of taxes vs outcome" solution.
This, to me, is the more interesting bit of the article.
I don't really know what a good solution looks like, but yeah, that's annoying.
Security firm KELA... has doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria.
If I was an evil hacker, I would only hack countries my country hated or did not have extradition agreements with. Like the Russian hackers do.Algeria has a extradition treaty with Romania:
https://periodicos.processus.com.br/index.php/egjf/article/v...
If their Opsec wasn't crap it is extremely difficult to try to identify them after the fact.
Registration is now compulsory on sales, but that only came in in 1990.
As to what I mean by binned, I mean literally binned, thrown away.
In Brazil the books are append-only, they have the whole history of thay piece of land since records began. If it was a bigger plot that was dismembered, it is there too. When ownership changes you have to register the contract/terms of transfer/sale separately in a different process, but that does not change legal ownership and you still must go to the registry and register that registered transfer/sale in the registry, and the paperwork you get is a new certificate of registration which is a new snapshot of the books and includes that whole history from the very beginning. There is no copy or certificate you can can get from the land registry without including that whole history.
Possibly since 1086
There's a growing (retarded) perspective, not only here in Romania but in most of the EU, that we must digitalize at all costs; this itself is obviously not a problem, but it usually comes with the removal of the "traditional" options too. The same goes for payments (removal of cash) and basically every aspect of the administration/society where this could be applied. The most recent concrete example for Romania is the mandatory digital signature by ANAF (IRS equivalent) for all companies.
Unlike other regions of the West: NA/WE/rest of the West (SK, JP, etc.), in EE, people (*younger generations, explained below) don't often think about the aspects of confidentiality that much, or if they do, they usually apply it incorrectly (either IRL [filming in public] or online ["I've accepted a draconian TOS that gives the company rights to all of my data, but I haven't actually read any of it, and now I'm invoking my "GDPR rights" against said company."]).
It does not take a genius or a historian to observe that while the older generations do not have this "problem" (they're very skeptical of the gov. [at least in certain aspects], in an almost american fashion — explained by the fact that they've experienced communism), younger generations position themselves in the extreme opposite; they despise the older generations ("boomers") for being luddites and somehow blame them for the gap in civilizational progress between WE and EE. There is a legitimate point here, of course, but it should be noted that the argument is almost always presented in an emotional, overwhelmingly irrational fashion, and almost never includes comparisons between the centralization done by the state in the past [communists] and the new one attempted by current govs [but digitalized]. (This delves into a broader socio-cultural divide between the generations that includes other aspects like religion, traditions, etc.)
The biggest portion of the so-called "IT people" who call for this "digitalization wave" are midwits, "inverse luddites" (they don't care about the implications), and, in smaller numbers, grifters and second-order beneficiaries (on the "digitalization" gov. projects). Obviously, it should be mentioned that, despite progress, nepotism and corruption are still present, and there are cases where gov. contracts are not given to the best candidate.
As a person who's both working in the IT sector and not a boomer (despite the impression of my comment), "we" should be careful about enabling totalitarians in our endeavors."Hackers" is just one reason out of a multitude of other reasons for not abandoning the sacred paper (see the ES+PT incident one year ago).
Why does full access include the ability to delete read only data that should never ever be deleted for the rest of time?
It's like building a self destruct button that ignites the physical records. It's an unnecessary risk to make such a dangerous thing.
Permissions inside the database should be segregated. The credential used by the webserver should not have enough permissions to DROP DATABASE. Just the appropriate selects/updates/inserts.
Likewise, if you are storing backups on the same network (as opposed to a tape backup), network permissions should allow writes/creates but not deletes.
> backup the attacker can reach is not a backup
you can have append-only backup systems.- We have 2 sources of data that we must backup to continue existing as a business; our postgres and binary files in S3. Everything else is derivable (elasticsearch, so on).
- For postgres, we use barman. With the help of opus/fable, you can get a streaming replication backup working in no time. We have one into another server in the same datacenter (we use baremetal) and another one in another server in a different datacenter.
- We then have a last resort barman backup with bi-weekly base backups + WAL streaming to S3 (both the base backup and WALs). It sends these backups + wal segments into an specific S3 bucket that has object lock in compliance mode. This is a feature from AWS S3 that even the most privileged account credentials (super admin) can't turn off nor delete the files before the object lock, which is 10 days in our case. Object lock compliance mode can only be extended, never shortened.
- For S3, we store them into another versioned bucket, with lifecycle rules to also expire non current versions (== deleted objects) after 10 days. No point in object lock compliance here because it would only protect objects for the most recent 10 days, and you gain nothing. What we do instead: the app servers only have access to these bucket tru an IAM credential that can't delete old versions (so deleted objects have to expire manually via the lifecycle rule) AND this IAM credentials also can't change the object policy.
IMHO, this protects us enough so that even in the worst case scenario (ransomware) we have 10 days to sort everything out and recover our AWS access.
And yes, we test the S3 barman restoration and it works fine. Data loss is at max 5 minutes due to the archive_timeout=300s on the primary.
For the streaming replications in the two servers I mentioned, it's less <1ms, but those wouldn't protect us much in the case of the ransomware - even tough we use tailscale and one compromised server can't ssh into the other.
The worst case is the company itself denying you access. More likely to happen with Google.
If your production system at most runs a backup to a drop site, then your backup facilities pull down versioned backups from there, you can better ensure older backup files are intact. More so by not allowing the two to see each other at all and not using backup accounts from a system that can access production resources.
No need to advocate on established best practices. The 3-2-1 rule and its variations are already common place and often mandated by standards/investors and partner contracts.
https://connection-technologies.co.uk/help/backup-disaster-r...
Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:
<https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...>
<https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...>
Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>.
NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.
Blizzard gave hardware tokens out to the entire convention one year. Smart phones became a variable not long after and then they didn’t make them mandatory but game guilds almost universally did. Especially for officers.
News at 11.
3 2 1 people.
Withno external backups piecing together all the lost functions must havebeen hair raising, and more forensic archeolgy than data recovery.
Last i heard i think they had restored a quarter of the lost services/data.