<- Back
Comments (245)
- skinfaxi> Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.
- cbg0An update from the land registry (the truthfulness of this remains to be seen depending on how fast this comes back online):ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.
- dredmorbiusPoor password practice and policy, and likely a lack of 2FA / physical token security, seem to have contributed to this breach.Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:<https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...><https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...>Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>.NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.
- alexpotatoRomanian friends have told me that this is really due to corruption.Specifically:- government gives IT/data contracts to cronies- cronies don't actually do any real security work to protect the data- things like this happen
- khursSecurity firm KELA... has doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria. If I was an evil hacker, I would only hack countries my country hated or did not have extradition agreements with. Like the Russian hackers do.Algeria has a extradition treaty with Romania:https://periodicos.processus.com.br/index.php/egjf/article/v...
- osinixThe backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.
- tiberius_pThe majority of people have paper documents from the land registry. Digitalization of the land registry is a fairly recent development in Romania so people almost always requests papers when they register their land. In the event that all the digital data or large parts if were lost it would be possible to reconstruct it from the papers and interpolate the missing parts if any.
- tracker1Offline and pull based backups FTW... This is why I advocate for a pull or at least push/pull model for backups... where the remote system pulls backups out of your production environment, or otherwise from a drop point. Because a corrupt production system that controls backups can corrupt backups.If your production system at most runs a backup to a drop site, then your backup facilities pull down versioned backups from there, you can better ensure older backup files are intact. More so by not allowing the two to see each other at all and not using backup accounts from a system that can access production resources.
- puritanicdevWell, the land registry database in Serbia hasn't been working for two months now; the government hasn't issued any announcement so far, except for generic system-issue information we get from LRD support. Weird, hopefully we weren't hit too
- ajbThe UK used to have a distributed system - everyone had to have a solicitor store "deeds" of their property, which were a sort of paper blockchain of all the transactions the land had been in since - I don't know, since records began I guess. Since we got a centralised land registry cheaper solicitors have binned these, but some properties still have them as a historical record.
- SquarexThe same thing happened to Slovakia not that long ago.
- danieldrehmerDibs on Vlad's castle
- mdavid626Why not just change ownership then? I'd bet some people would be interested to pay some money for that...
- javawizard> HuggingFace got hacked by an AI. What stuck out to me was the guardrail asymmetry. The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models.This, to me, is the more interesting bit of the article.I don't really know what a good solution looks like, but yeah, that's annoying.
- luciana1uwe spent centuries building a system to track who owns what land and then put the whole thing in one database that can be deleted with a single compromised password
- anonundefined
- 21asdffdsa12Imagine if the hacker was more clever and started writing plausible nonsense into the database, corrupting the backups.
- nailz1911arte.tv released a documentary about measuring and registering land just a month ago @ https://www.youtube.com/watch?v=fl7AfiJs5Gk (Romania: The Unmeasured Land | ARTE.tv Documentary)
- UltraSaneEnterprise storage arrays have immutable snapshot functionality that makes ransomware easy to recover from.
- RandomLensmanWhat's wrong with an old fashioned paper registry then?
- m0lluskSeems like property ownership histories could be one of the few good applications of blockchain technology.
- riazrizviMany many times, entire armies have been sent in to adjust another country's land registry.
- rimworldaka tokenize everything
- anonundefined
- charcircuitWhy is deleting the whole database a valid operation? The system should make that impossible.
- iamgopalwould blockchain could have prevented it ?
- arisAlexisWe will see a lot of those with open source Mythos equivalent models.
- sebow[Fairly off-topic and political]There's a growing (retarded) perspective, not only here in Romania but in most of the EU, that we must digitalize at all costs; this itself is obviously not a problem, but it usually comes with the removal of the "traditional" options too. The same goes for payments (removal of cash) and basically every aspect of the administration/society where this could be applied. The most recent concrete example for Romania is the mandatory digital signature by ANAF (IRS equivalent) for all companies.Unlike other regions of the West: NA/WE/rest of the West (SK, JP, etc.), in EE, people (*younger generations, explained below) don't often think about the aspects of confidentiality that much, or if they do, they usually apply it incorrectly (either IRL [filming in public] or online ["I've accepted a draconian TOS that gives the company rights to all of my data, but I haven't actually read any of it, and now I'm invoking my "GDPR rights" against said company."]).It does not take a genius or a historian to observe that while the older generations do not have this "problem" (they're very skeptical of the gov. [at least in certain aspects], in an almost american fashion — explained by the fact that they've experienced communism), younger generations position themselves in the extreme opposite; they despise the older generations ("boomers") for being luddites and somehow blame them for the gap in civilizational progress between WE and EE. There is a legitimate point here, of course, but it should be noted that the argument is almost always presented in an emotional, overwhelmingly irrational fashion, and almost never includes comparisons between the centralization done by the state in the past [communists] and the new one attempted by current govs [but digitalized]. (This delves into a broader socio-cultural divide between the generations that includes other aspects like religion, traditions, etc.)The biggest portion of the so-called "IT people" who call for this "digitalization wave" are midwits, "inverse luddites" (they don't care about the implications), and, in smaller numbers, grifters and second-order beneficiaries (on the "digitalization" gov. projects). Obviously, it should be mentioned that, despite progress, nepotism and corruption are still present, and there are cases where gov. contracts are not given to the best candidate.As a person who's both working in the IT sector and not a boomer (despite the impression of my comment), "we" should be careful about enabling totalitarians in our endeavors."Hackers" is just one reason out of a multitude of other reasons for not abandoning the sacred paper (see the ES+PT incident one year ago).
- ExoticPearTree[flagged]
- DigitResort[flagged]
- spwa4Amateurs. Everybody knows you should never wipe databases. You should install a cronjob that makes a random, unrecoverable change on a regular (but random) basis.
- anonundefined
- hughwWas hoping it was a political act in favor of land reform or against owning property.
- c7bFinally, AI is giving us some real-world blockchain use cases (assuming the attack was helped by AI). Only half joking, BFT is petty much the most adversary-proof security guarantee we can get in a distributed system.