A case study in why credentials are revoked before firings.

top 50 comments

sorted by: hot top controversial new old
[–] 174 points 4 months ago (21 children)

Why were they storing passwords in plaintext in the databases?!

  • source
  • hideshow 21 child comments
  • [–] 50 points 3 months ago (3 children)

    Why not? National Safety Department of Slovak Republic (Narodny Bezpecnostny Urad) had password NBUSK123… just government things

  • source
  • parent
  • hideshow 3 child comments
  • [–] 44 points 3 months ago (6 children)

    Because like all critical infrastructure it was setup by somebody's kid on work experience

  • source
  • parent
  • hideshow 6 child comments
  • [–] 20 points 3 months ago (5 children)

    Or some poor guy who is setting it up, because it is a one off and just get it done project, that metastasizes into a fucking mess.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 7 points 3 months ago (4 children)
  • [–] 18 points 3 months ago

    It's like leaving your car door unlocked in a bad neighborhood so your window doesn't get smashed for the $.36 in the center console. Attacker might take the prize and go without showing that everything around it is just as poorly-built.

  • source
  • parent
  • [–] 8 points 3 months ago (5 children)

    Probably for the same reasons web browsers store them in plain text: They don‘t care.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 18 points 3 months ago (4 children)

    the same reasons web browsers store them in plain text

    Why one web browser stores them in plain text. Fucking Edge.

    Who knows about the others, but I can pretty much guarantee you that Librewolf, for example, isn't doing that shit.

  • source
  • parent
  • hideshow 4 child comments
  • load more comments (1 reply)
    [–] 112 points 3 months ago* (8 children)

    Back in 2015, the brothers pled guilty in Virginia to a scheme involving wire fraud and computers. Muneeb was sentenced to three years in prison, while Sohaib got two.

    I'm not gonna say there were signs that these two weren't the most law abiding of citizens to begin with, buuuuut...

  • source
  • hideshow 8 child comments
  • load more comments (1 reply)
    [–] 109 points 3 months ago (7 children)

    And why couldn’t they have done that to the student loans system?

    Like JFC, they could have instantly made themselves immune from trial-by-jury anywhere in America by doing that one tiny thing.

  • source
  • hideshow 7 child comments
  • [–] 86 points 3 months ago* (3 children)

    Muneeb Akhter asked Sohaib Akhter for the plaintext password

    The more scary part in this story is that the government stores your passwords in plain text!

    So basically ANYONE with access to the database can steal your credentials, including employees, the government and any authorities.

    Never re-use passwords.

  • source
  • hideshow 3 child comments
  • [–] 18 points 3 months ago

    Every place I have worked, most of HR and like half of finance/accounting has access to your social security number, full address and phone number. Sometimes even the password and security questions you used for whatever BS portal they made you setup an account in.

  • source
  • parent
  • [–] 64 points 3 months ago (2 children)

    To be fair, what else could they do with that keyboard.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 40 points 4 months ago

    Only a living wage can prevent data dumps.

    Upper management can't even see it...yet.

  • source
  • [–] 34 points 3 months ago (7 children)
  • [–] 38 points 3 months ago (4 children)

    Try not to delete any databases on your way to the parking lot!

  • source
  • parent
  • hideshow 4 child comments
  • load more comments (2 replies)
    [–] 32 points 3 months ago (1 child)

    “Eh, they can recover from yesterday,” he said, referring to daily database backups.

    But did they recover from backups? Don't leave the most juicy intrigue out of the story.

  • source
  • hideshow 1 child comment
  • [–] 28 points 3 months ago (13 children)

    Its always interesting when people are both very smart and also very stupid at the same time.

  • source
  • hideshow 13 child comments
  • [–] 17 points 3 months ago (12 children)

    Knowledgeable and smart are not the same thing. These two are very knowledgeable about the systems they worked on and database manipulation, believe it or not these are not hard skills to learn. But they were incredibly dumb regardless given every single action they took at every point in their lives.

  • source
  • parent
  • hideshow 12 child comments
  • [–] 10 points 3 months ago (11 children)

    Fun fact. In psychology assessment this are being called hard skills: very technical abilities for doing specialized tasks; and soft skills: social and emotional abilities to navigate social contexts, manage conflict and self regulate emotions.

    Hard skills are easier to teach, while soft skills are very hard.

  • source
  • parent
  • hideshow 11 child comments
  • load more comments (10 replies)
  • [–] 13 points 3 months ago

    Redundant twin brothers to handle the redundant twin backups.

  • source
  • [–] 13 points 3 months ago* (last edited 3 months ago) (4 children)

    Muneeb and Sohaib Akhter, now both 34, had been in trouble before. Back in 2015, the brothers pled guilty in Virginia to a scheme involving wire fraud and computers. Muneeb was sentenced to three years in prison, while Sohaib got two.

    They had a track record and found employment in government IT

    HR should've been fired for that fuckup.

    A case study in why credentials are revoked before firings.

    No. A case study against employing known criminals.

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 10 points 3 months ago

    Commits hundreds of crimes then starts bringing up god. Class act.

  • source
  • load more comments
    view more: next ›