A sample of 5,000 alleged agents seen by 404 Media includes names, addresses, phone numbers, and details on FBI employees' spouses.
614 comments
China hacked 22.1 million records of US government employees:
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.
We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.
Ask the Iranians how impenetrable even physical isolation actually is - their centrifuges were still destroyed even though they were air gapped (the infamous Stuxnet). Ultimately all computerized systems are vulnerable to sufficiently determined cyber-adversaries.
You also need to make various cost-benefit analysis decisions for all of these things. Does the extra security you gain by keeping your system disconnected from the Internet actually increase all-around availability and resilience?
In particular, integrating highly variable power sources like solar and wind into the grid requires much more complex synchronization between producers, storage, and consumers in order to function properly. Trying to build a renewable grid without Internet access is doomed to extremely inefficient, if possible at all. Building an alternate network would be extremely expensive and ultimately useless (since every house in the country needs to connect to it, it would be just as vulnerable as the actual Internet anyway). So, ultimately you must connect your power grid to the Internet to actually provide service, despite the security risks.
Perhaps the situation with the water supply or traffic is different, so maybe this is not as applicable.
The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like.
It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.
Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.
Nobody I know in security hardening or vulnerability research has ever believed that anything is perfectly secure. It's not black and white. There are degrees to this.
I find this fatalistic thinking that every database should be assumed compromised to be subtly harmful. Everyone I know who thought that way waltzed right into lax security practices. "Good enough, what's the point, if anyone wants it bad enough they're going to get it anyway"
CHC is the largest claims clearinghouse in the US; about 100m people's insurance claims go through there each year.
The hackers asked for a ransom ($35m iirc) to delete the data, which United Healthcare (who owns them, because of course they do) paid. But it seems that the collective negotiating on behalf of the actual hackers rug pulled, so the actual hackers didn't get paid.
This is more than simply medical records. It includes who is active duty military and their family. If you can map where soldiers are, you know roughly the size of different military bases. If you know which types of capabilities are operated out of which bases, you can get a pretty good look of how the US is allocating personnel.
It was crazy working on recovery from this at the time. It should have been front page news, but wasn't.
I guess your parking history around town could be valuable if someone is targeting you.
The HuggingFace incident was audited by independent third party analysts. To "orchestrate" that and keep it a secret is like faking the moon landing. To many people involved. It's not feasible.
OpenAI was founded to develop safe AI. Then Anthropic split off because OpenAI was not safety focused enough. These companies have been railing about AI safety long before they had these big boy valuations. Many people at OpenAI/Anthropic explicitly joined to help make AI safe. This is not some top-down company value.
Also, I seriously doubt that "making panic" is actually good for the stock price. Usually any companies natural reflex is to cover up safety risks. That's not to say that these companies are angles. Of course they're pulling some shit but that doesn't mean that everything out of their mouths must be lie.
Right after the HuggingFace incident, we all saw how every company clamored to claim how their AI models have also broken out of Sandbox, and hacked some stuff. As ridiculous as it was, they all used that to demonstrate their model's capabilities.
Yes, HuggingFace was audited by a third-party. But said third-party wrote that they had to use unreliable AI in their conclusions (page 26) because they had six days to analyse 1300 (page 70) chains of thought and 70000 messages.
> OpenAI was founded to develop safe AI.
If that were the case, then they would have followed their own report saying not to release GPT-3. Or, if they were following their own founding principles, they wouldn't have stopped releasing models due to (in their own words) the challenging market.
That doesn’t mean the AI vendors doing reckless testing isn’t itself dangerous, it very much is
Given the "AI race" narrative, it makes them indespensible to the US government and too big to fail. An investor's dream
In the pilot, the Galactica was literally being turned into a museum, and that's why they lived.
That is exactly the canon.
I think you missed the point of "no networking", you have to actually physically sit in front of the computer. There is no remote access.
They should try something like "100 agents at noon on Sep 23 do the chicken dance for 30 min in the middle of the street in DC, then we'll consider not releasing the info and not sell it to the Chinese".
If they're just a bunch of common crimimals from China or Russia, I doubt they'll appear in court.
American courts are real scary when you live in a country that works together with the USA, but if you don't, all you need is to make sure your crimes aren't worth starting another invasion over.
>That defacement says, “this site has been seized by ShinyHunters,”
No archive but at least a screenshot: https://cyberinsider.com/wp-content/uploads/2026/09/fbi-site...
>https://news.ycombinator.com/item?id=49807388
The photo they put is a Pokemon so yeah probably their name is from it.
They mention hindering trust because for an extortion gang, they want companies to trust that they won't leak the data in order to make it seem worthwhile to pay.
Read the full thread on Hacker News →
Related stories
- The Verge · 0 points · 3 days ago
- Hacker News · 1 points · 2 days ago
- Hacker News · 421 points · 6 days ago
- Hacker News · 3 points · 3 days ago
- Hacker News · 1 points · 4 days ago
- Hacker News · 1 points · 6 days ago