Skip to content

Berlin is being blackmailed by hackers

bbc.com
62 pointsdudefeliciano26 comments
On HN

Comments

How could this have been prevented?

Serious question that anyone familiar with the "Verwaltung" (Administration) here in Berlin should ask themselves. Because the fact is, it couldn't have been.

For one thing, how does one analysis and find vulnerabilities in a system? By doing pen-testing but is that legal here? Why didn't someone from the CCC[1] or BSI[2] actually do a pen-test and discover the vulnerability that was used?

Particularly the CCC who like to point fingers and complain about how bad security is. Why didn't they simply do a pen-test and tell the "Verwaltung" about what they found? Probably because they knew that the "Verwaltung" would proceed with legal fixes instead of system fixes, i.e., making hacking even more illegal than it already is.

Meanwhile all the Consultants that the city pays pretended everything was super secure because well ... well because it all Microsoft so it must be secure. We even have the licenses to prove it.

[1] https://en.wikipedia.org/wiki/Chaos_Computer_Club

[2] https://en.wikipedia.org/wiki/Federal_Office_for_Information...

I think it has to do with the fact, that "white" hacking is illegal? I am sure people would like to help out and harden the systems.

But i am also not sure, what actually happened. Once ya in a system, all is lost.

And the culture around credentials is in my opinion a lost case anyways. I do not know where IT has gone a wrong path. Either security it is super high and you can not do anything (hello bureaucracy) or you can do more, but you become more vulnerable.

Anyways. Data is the new Oil, government said.

Allegedly hackers gained access to data about true DSL speeds in Berlin's households, waiting times for Anmeldung, and scandalous ratio of rental deposit returns from landlords. In short Berlin is cooked but it also always has been.

Isn't 2 million euros a bit of a lowball demand for a city the size of Berlin? In any case, it's good they're not paying.

That‘ll teach the bad guys! Pity about all those that will have their private data auctioned off.

I‘m sure that the good guys will catch the badies in the nick of time to prevent a data auction.

Just in time for a good game of tennis and a happy end. Thanks to Hollywood we have nothing to worry about.

I‘m glad _they_‘re not paying and really looking forward to having my private data turn up somewhere I never intended due to _their_ incompetence. I’m sure _they_ can’t help it because of course _they_ aren’t at fault - it was the badies.

I'd rather they not pay and my data gets leaked along with everybody else's, than for them to pay and give incentives for future blackmail.

Not like Berlin could have paid anyway.

https://www.youtube.com/watch?v=fqb6qYBdvX8

There’s no information of what was leaked besides ~5TB of data? And since they don’t intend to pay then they’ll just pretend nothing happened?

Neither the media nor politicians are interested in hyping up the issue right before the state election on Sep 20. So it's probably just what you suggested: pretending that nothing happened.

Anecdotally from another EU country, the politicians simply insolently ignore the data leaks. Victims will be punished though with a wave of "beware of scammers" communication, increasingly invasive identification, and institutional erosion of their privacy.

And because it's a government, it doesn't have to comply with any of the data breach laws.

literally not how it works.

"Two of the worst people you know are fighting."

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.