| ▲ | jacobgold 2 hours ago |
| At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors. China hacked 22.1 million records of US government employees: https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... |
|
| ▲ | coldpie an hour ago | parent | next [-] |
| It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else's Internet-connected computers. For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it. The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house. |
| |
| ▲ | josephg 23 minutes ago | parent | next [-] | | > It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible. We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay. | | |
| ▲ | msla 12 minutes ago | parent | next [-] | | The bank has the best doors, the best locks, and the best cameras, and it is patrolled by a guard who props the doors open to so he doesn't have to keep fooling with the locks and points the cameras the other way to extend his smoke break. SeL4 would be another system used by humans. | | |
| ▲ | timschmidt a minute ago | parent [-] | | It's always possible to break a perfect system by moving an additional layer of abstraction outward, and attacking one of the assumptions upon which it's built. Some of our era's highest security systems - game consoles - have been broken by undervolting them until the logic failed. |
| |
| ▲ | bjtitus 15 minutes ago | parent | prev [-] | | [dead] |
| |
| ▲ | shepherdjerred an hour ago | parent | prev | next [-] | | It used to be that nothing was secure but that was OK because at least adversaries would have to expend effort. If you are one of a million companies why would anyone hack you. Maybe if you are a target you need a lot of investment, but most orgs only prevent the most egregious of vulnerabilities. The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like. It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems. Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change. | | |
| ▲ | Veserv 2 minutes ago | parent | next [-] | | Ah yes, the parable of the bear. There are a million people stuck in a valley and two bears. You do not need to outrun the bears, you just need to outrun at least two other people. But it turns out one of those bears is male and the other is female. So next year there are more bears, but you still just need to outrun a few people. Then one day, there are 1 million bears and they eat you all. Very inspiring story. Software security has just been a fun time of ignoring the exponentially growing number of bears for the last few decades so you can continue to use systems unfit for the threat landscape because they are cheap. | |
| ▲ | pixl97 an hour ago | parent | prev | next [-] | | >The calculus has certainly changed. Adding AI into this really is just changing it to how much money your adversary is willing to spend to break in. The moment one crack in the armor shows up countless agents with unending patience can start embedding themselves everywhere in timeframes way faster than human actions. You could quickly find out all the special sauce for your company has been copied who knows where. Working with banks when the Glasswing/Mythos first came out and they were given access to it has given me direct access to their infosec departments that are panicked. They've been sitting on piles of bugs for years that were low risk enough, and they have seen in their own tests how fast they can be probed. Worse those infosec systems that have identified the risks in their software that aren't yet fixed are nuclear waste vats just waiting to get spilled to the wide world. | |
| ▲ | BoxwoodSeed an hour ago | parent | prev | next [-] | | I am reminded of the scene of a guy walking through various layers of security to access a computer that isn't connected to any network and still wonder what the hell this guy's job was in Mission Impossible (1996). The data got stolen either way, because of course it did, but what highly sensitive work can you even do on a computer not connected to any network? If there's too much security in the way, it seems to me that work becomes impossible. | | |
| ▲ | coldpie 39 minutes ago | parent [-] | | We had water and traffic control and electricity for decades and centuries before the Internet. It is less convenient and more expensive, but it also means hostile countries can't literally poison your drinking water from across the planet. It's not a difficult trade to consider. |
| |
| ▲ | throwup238 an hour ago | parent | prev [-] | | > It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems. Admiral Adama says otherwise. | | |
| ▲ | shepherdjerred an hour ago | parent | next [-] | | The military has significantly different incentives. Even just consider banks and e-commerce. They are hugely lucrative and making them even a tiny bit less accessible directly impacts their revenue. As an example, Amazon seeing that latency has a measurable effect on purchase behavior. Maybe the military (fictional or otherwise) can go back to the ARPANET but most economic activity created by the internet cannot afford to disconnect | |
| ▲ | kridsdale1 28 minutes ago | parent | prev | next [-] | | So say we all. | |
| ▲ | pixl97 an hour ago | parent | prev | next [-] | | I mean he is a fictional character. In the real (fake?) world the toasters would shoot smart dust all over your crap that would assemble back on your circuits creating radios between all the different components. They were fighting an adversary that was far more advanced than them. | |
| ▲ | SilentM68 an hour ago | parent | prev [-] | | That's actually funny. I was going to add Gipsy Danger being analog, but it's a totally different scenario. |
|
| |
| ▲ | GolfPopper 32 minutes ago | parent | prev | next [-] | | Many years ago, I regularly played cyberpunk tabletop RPGs with a number of other computer-inclined friends. We all used to laugh at ridiculousness of a key assumption of the game - the idea that giant corporations would ever connect their internal networks, full of valuable data, to the larger global telecommunications network. | | |
| ▲ | shockwaverider 28 minutes ago | parent | next [-] | | What could possibly go wrong - I worked in intelligence in the 80s and one day there was this story about the office of personnel management being hacked and I was like “Thank God all my shit is on microfiche in some dusty basement filing cabinet, like who would be so stupid as to scan that shit into a computer?” Sure as shit, like a few months later I get the letter that my whole TS/SCI clearance documents had been stolen :-) | |
| ▲ | usumgallu 4 minutes ago | parent | prev [-] | | [dead] |
| |
| ▲ | sekh60 24 minutes ago | parent | prev | next [-] | | This. I have an OpenStack homelab and a fast home internet connection. I update things pretty much daily, apply best practices, etc. And despite that outside of a wire guard instance i still host public things on a pair of VPSes, security just moves too fast to risk the home network (important things are backed up remotely and all that). I try to update the VPSes daily. Haven't gotten popped yet (to my knowledge!), but I am sure it'll happen eventually. | |
| ▲ | sippingabonedry an hour ago | parent | prev | next [-] | | A generation of coders who can't/are scared to write "Hello world" in C without Claude doing it for them has not helped. | | |
| ▲ | passwordoops an hour ago | parent [-] | | I think you're exaggerating a bit. Does this answer your question? /s | | |
| ▲ | sippingabonedry an hour ago | parent [-] | | I've seen it. People flaunting their credentials in multiple languages, then sweating bullets and apologizing profusely when they see int t = 4;
You can either code or you can't; the language is merely a vehicle. | | |
| ▲ | BoxwoodSeed 35 minutes ago | parent [-] | | I agree, but then learning to code isn't much of a hurdle. It's a similar effort to learning vim. The difficult part is getting to know the language. I never coded in Haskell for example and learning to use that language would take effort. On the other hand, it would be pretty easy with an LLM at hand. It might even help in figuring out whether Haskell would be a good fit. Something I couldn't do, as I do not know the language. Then again, it's not a question that really gets asked much in a corporate setting. Most things are just solved in a few popular languages, whether that makes the most sense or not. | | |
| ▲ | autoexec 10 minutes ago | parent [-] | | > learning to code isn't much of a hurdle... The difficult part is getting to know the language. I agree. The people who depend on chatbots to write their code for them won't have either of those skills though. They don't know (or are in the process of forgetting) how to code, and they're missing out on the opportunity to really learn the language by turning off their brain and letting a bot spoon-feed them code. An LLM would only get in your way if you actually wanted to learn Haskell. |
|
|
|
| |
| ▲ | drdaeman 34 minutes ago | parent | prev | next [-] | | There is such a thing, or, rather, used to be. Problem is that security is expensive (essentially one needs to examine all possible states of the system), and it inevitably failed to keep up with the crazy growth of complexity of modern computer systems. It became impossible to maintain a model of a system with myriad of moving parts, so it became impossible to make behavior guarantees. Remove the complexity (all the way down to the hardware quirks), and security will be doable again. | |
| ▲ | skybrian 43 minutes ago | parent | prev [-] | | If there were companies that never got hacked, how would you notice? |
|
|
| ▲ | titzer an hour ago | parent | prev | next [-] |
| And the city wonders why I don't want to put my credit card info in their crappy parking app and would instead prefer to put a quarter into the meter for 30 mins. |
| |
| ▲ | MrDrMcCoy 12 minutes ago | parent | next [-] | | That what services that offer disposable and merchant-locked virtual cards are for. I have had good experiences with Privacy.com and Revolut. | |
| ▲ | lotsofpulp an hour ago | parent | prev [-] | | What info can be gleaned from that? Surely the mere fact that you have a credit card means your name and billing address are floating around. I guess your parking history around town could be valuable if someone is targeting you. | | |
| ▲ | ceejayoz an hour ago | parent [-] | | > What info can be gleaned from that? The card number? | | |
| ▲ | chrsstrm an hour ago | parent | next [-] | | In 2026, having my credit card number compromised is the least of my worries. At least here there is an established process for denying charges and ordering a new card. As long as you're not using a debit card, this is not a big deal. | | |
| ▲ | pixl97 43 minutes ago | parent | next [-] | | Ok, your card is compromised. It's been cancelled. One, how much money is in your pocket so you can eat? ok, you'll use your second ca.... oh, it has to be cancelled now too. Ok, lets wait a few days for another card, and lets go use it the first time, what hacked already, I guess I need to wait a few more days. >As long as you're not using a debit card, this is not a big deal. So screw 60% of all transactions done on a card? This doesn't seem workable. | | | |
| ▲ | dylan604 an hour ago | parent | prev [-] | | My bank will reverse debit card charges. Based on that, I assumed that was a standard thing now. | | |
| ▲ | bluGill an hour ago | parent [-] | | The problem is debit cards leave a window where you don't have access to your own money until it gets reversed. | | |
| ▲ | dylan604 26 minutes ago | parent | next [-] | | Only time I've seen that is the stupid holds that hotels do for deposits. The time I had the bank correct a debit card issue had the money available immediately. The only real hold on the account was waiting for the new card to arrive, but the funds were available | |
| ▲ | asdff 27 minutes ago | parent | prev [-] | | What happens with credit card? Is your line of credit reduced until it gets reversed? |
|
|
| |
| ▲ | Barbing an hour ago | parent | prev | next [-] | | In USA, folks who check their statements monthly are at little risk of immediate financial pain there. When your lifetime of credit card transactions leaks, that could be financially painful, embarrassing, etc. (can be discriminated against, including with pricing) I do dislike creating a log of where I park on some random company’s server. Nice that ALPRs/govt.-funded corp spycams/Ring/etc. make sure the quarter method is minimally marginally effective at protecting privacy. | | |
| ▲ | ceejayoz an hour ago | parent [-] | | > In USA, folks who check their statements monthly are at little risk of immediate financial pain there. I had to fight a bank for months over a clearly fraudulent charge. Sometimes it's easy; other times it isn't. |
| |
| ▲ | dylan604 an hour ago | parent | prev [-] | | who stores card numbers other than the processors? that should be a hangable offense. I've integrated card processing on multiple sites, and not once does the form come from me. I add the processor's JS, and it collects the data to move along. They then return to me a bit of information that includes success/fail so that I can decide what to do from there. | | |
| ▲ | ceejayoz an hour ago | parent [-] | | > I add the processor's JS, and it collects the data to move along. Consumers aren't gonna notice the difference if the site gets hacked and that JS is swapped out for a malicious set. | | |
| ▲ | pixl97 41 minutes ago | parent [-] | | Yea, it's insane seeing this person arguing about the nature of credit card theft when we have a million different examples of how it happens and how rarely the end user knows until it's far too late. We almost always learn about itpost ad hoc. | | |
| ▲ | dylan604 24 minutes ago | parent [-] | | You've moved the goal posts. A typical site isn't storing the numbers so when they get hacked, that data is not available. If you're suggesting hackers directly injecting malicious JS to hijack card data then that's totally different. I'm not insane about this particular subject. You're just standing on a soapbox | | |
|
|
|
|
|
|
|
| ▲ | clickety_clack 20 minutes ago | parent | prev | next [-] |
| This can’t be true. There’s no way the lowest bid contractor would build something with security gaps. |
|
| ▲ | Taek 2 hours ago | parent | prev | next [-] |
| Google seems capable |
| |
|
| ▲ | primitivesuave an hour ago | parent | prev | next [-] |
| The recent Epic vs Health Gorilla lawsuit is an example of how your medical records have almost certainly made it to the hands of many people you will never know about. |
|
| ▲ | tdhz77 an hour ago | parent | prev | next [-] |
| Mythos can do much worse |
|
| ▲ | ChosenEnd an hour ago | parent | prev | next [-] |
| Mythos can hack 200 million government employees |
|
| ▲ | simur an hour ago | parent | prev | next [-] |
| Yeah, about the medical information. Recently in Poland there was a hack on the medical system called MyDr that is used by commercial medical facilities.
Estimated 21M people could've been affected.
So it is already happening and the scariest thing is, we don't have control on where our data is stored on. Even the EU GDPR didn't make it easy to control what data lands where. |
|
| ▲ | kakacik an hour ago | parent | prev [-] |
| banks still largely do... if they lose this fight, society has a problem |