| ▲ | Towaway69 2 days ago | |
How could this have been prevented? Serious question that anyone familiar with the "Verwaltung" (Administration) here in Berlin should ask themselves. Because the fact is, it couldn't have been. For one thing, how does one analysis and find vulnerabilities in a system? By doing pen-testing but is that legal here? Why didn't someone from the CCC[1] or BSI[2] actually do a pen-test and discover the vulnerability that was used? Particularly the CCC who like to point fingers and complain about how bad security is. Why didn't they simply do a pen-test and tell the "Verwaltung" about what they found? Probably because they knew that the "Verwaltung" would proceed with legal fixes instead of system fixes, i.e., making hacking even more illegal than it already is. Meanwhile all the Consultants that the city pays pretended everything was super secure because well ... well because it all Microsoft so it must be secure. We even have the licenses to prove it. [1] https://en.wikipedia.org/wiki/Chaos_Computer_Club [2] https://en.wikipedia.org/wiki/Federal_Office_for_Information... | ||
| ▲ | okr 2 days ago | parent [-] | |
I think it has to do with the fact, that "white" hacking is illegal? I am sure people would like to help out and harden the systems. But i am also not sure, what actually happened. Once ya in a system, all is lost. And the culture around credentials is in my opinion a lost case anyways. I do not know where IT has gone a wrong path. Either security it is super high and you can not do anything (hello bureaucracy) or you can do more, but you become more vulnerable. Anyways. Data is the new Oil, government said. | ||