Hackers post 25,971 files stolen from Broward schools
sun-sentinel.com
sun-sentinel.com
This kid is going places. Possibly jail, but definitely places
If I had broken my laptop and was honest about it, they'd have gossiped about me, a child, as if I should have the sensibilities of an adult. They might have also gossiped about my parents. They wouldn't worry too much if I overheard—perhaps even making a point of it to 'teach' me something. They definitely wouldn't worry about their kids overhearing it, and then I'd have to deal with them judging me too (read: using it as an excuse to try to bully me). If one of their own bullying kids was the reason my laptop was broken I'd have gotten to deal with being called a liar on top of it all, which would have been an even bigger excuse to try to bully me.
Thing is, if I'd have broken it, I'd have done odd jobs and saved allowances to repay it. That wouldn't have changed anything about the community response, though.
First you assume the family is poor. Second, you assume the laptop was _accidentally_ broken. Third, you assume the family has no other computer.
From what evidence do you draw ANY of your conclusions?
Plenty of rich or middle-class individuals steal things. It's not just the poor.
For a $300 iPad, they charge $100 for the first repair, then $500, then $1000. So these are penalties not repair fees. This iPad is expected to last through elementary school or middle school, so multiple years.
This is hard for an elementary schooler or even middle schooler and the risk of damaging these things, oddly they do not provide cases but allow students to buy their own.
I’d rather go back to paper books that are very hard to damage.
The school hired an “iPad wrangler” and cover their salary through the penalty fines. So it’s more expensive than just buying AppleCare. It’s also worse as it takes forever to get service and it’s faster to just go into an Apple store.
I’m not poor, but don’t have hundreds of dollars. Here’s some examples of charges- 1) iPad doesn’t work, school claims student damaged it but doesn’t know what is broken or what could have caused the failure, penalty charged, iPad replaced, no appeal possible, iPad wrangler (who has no credentials or training or skills in iPads) rules definitively; 2) another student knocks iPad out of hands onto floor breaking, penalty charged to steward not to knocker; 3) stolen, penalty charged
It’s implemented quite stupidly at school with no insurance and no skills for repair. 8+ year olds have a hard time protecting expensive electronics.
Not mention that the devices have spyware reporting all activity, not allowing messaging to parents and guardians, and not providing logs or audit to parents and guardians.
It’s funny that I dreamed of stuff like a Young Lady’s Illustrated Primer and we get this Brazil-like implementation where everything sucks, but digitally.
I had stuff like this happen to me in school; my family was not well off, so it was a fun prank for the kids who had money to 'accidentally' break or lose my things that I couldn't get replaced.
Remember, classism is taught early.
Is this a thing where you live, putting kids into jail for something as worthless as a laptop?
Everyone has got half a dozen old laptops in their basement nowadays, I can hand over 3 to them if that's what they need to keep them out of prison.
phew, close one
$20 million sounds like a lot to "improve cyber security", but I'm not involved in that industry. Can anyone with relevant experience share if that's a realistic budget?
/s
School boards are a special mix of corrupt and incompetent and it can be hard to tell which is the cause for any particular bad decision they make.
However, cybersecurity spending is effectively worthless from an outcome perspective as even Fortune 500 companies allocating hundreds of millions of dollars per year to cybersecurity can not protect against attackers with ~$100k. Given that the hackers were demanding $40M, there is no commercial IT system in the world that would even claim to make such an attack unprofitable let alone actually be able to do so. The best systems are somewhere on the order of ~10% of that level, so we would need systems literally 10x better than the best currently available commercial IT systems for it to even be possible to get adequate cybersecurity against this attack.
[1] https://en.wikipedia.org/wiki/Broward_County_Public_Schools
[2] https://www.browardschools.com/cms/lib/FL01803656/Centricity... Page 35
[3] https://www.browardschools.com/cms/lib/FL01803656/Centricity... Page 36
On one end of the spectrum, we have my local taco truck which makes decent business having zero web presence at all, and of course various local convenient stores and other small shops who might be doing their books in excel, not much different really than how they did their books when they bought paper spreadsheets from the store. These small businesses are uniquely immune to a hacker. What would or could a hacker even do to something like a locksmith or a liquor store? Not much I don't think.
There must be some lessons from this low tech way of doing business that can be carried over to large businesses, who have probably been oversold technology for decades by vendors looking to make sales. Maybe larger organizations should operate more like federations of smaller businesses. Like a franchise system but even more decentralized, using as little technology as possible, and the oldest, most proven tooling available to solve the job when technology is needed, rather than the newfangled thing everyone is blogging/tweeting/selling to you (that could probably be done with some awk).
That being said, we’d need to also make it illegal (with a bigger fine) to not inform customers of the breach, and to provide reduced damages for companies that promptly inform users. Otherwise the “correct” approach for a company would be to ignore every hacking attempt and never investigate.
Sure, but fining someone for leaking data is a very different thing than making them liable for damages, even if you call the fine "statutory damages".
Police misconduct gives rise to lawsuits. I'm sure one of the hopes of the plantiffs is that they change the system.
So, there is some precedent for lawsuits against public bodies in an attempt to change their behavior. I am somewhat skeptical about their utility in affecting institutional change, but there is definitely research on the subject and not just HN comments.
Fire the people responsible and make them unable to work for a district for five years.
It's hard to imagine anyone with half a brain working under such conditions.
It's also hard to imagine that putting such a measure in place would not result in data and systems being so locked down that they become unusable to most staff.
There needs to be real audits, with teeth, of computer security stuff - audits run in an adversarial way without the issues involves in financial audits. If you pass the audit, the fines should be minimal in the event of a breach.
https://www.documentcloud.org/documents/20535698-ransom-chat...
A number of things they say indicate English isn't their first language: "We could wait you forever", "your revenue is more than 4 billions. So it is a possible amount for you."
https://www.wlrn.org/local-news/2021-04-21/fdle-arrests-brow...
Eg the school principal is accused to be responsible for the 2018 parkland shooting, and several other financial misdeed related to safety measures after the shooting. And his base salary is 335.000. It's the 6th largest school district in the nation. It's annual budget is over 3 billion.
"The charges involve a range of alleged crimes, from bribery and bid tampering to lying and leaking."
The closest to any royal I could find is Marilyn Mansion as alumni. But they have many sports clubs with Royal in their name.
Fuck you too
> We are engaged on the issue
No you're not, the GDPR has been active for 3 years now, or 5 years if you include the time where it wasn't mandatory, if you were engaged it would have been fixed already.
> and committed to looking at options that support our full range of digital offerings to the EU market.
Yea, so how about the option of just disabling privacy invading code on your website, which would probably take much less than 3 years?
> We continue to identify technical compliance solutions that will provide all readers with our award-winning journalism.
More repetition of the same empty "we're DOING SO MUCH!".
But well, at least it doesn't say "We care about our European readers" like most of such blocked websites say.
That one usually makes my blood boil: You're not caring at all. If you were caring, you wouldn't lock out 448 million people for years!
- We live in a highly globally interconnected society. Actions everywhere on the planet have consequences everywhere on the planet. If the US fabric of society blows up after their previous clinically insane president incited violence for years, that WILL have consequences for Europe. If only for the thousands of nukes they have and the trillions they spend on military and invading unstable regions.
Also remember that we're being asked to spend tons of money on the NATO to aid in defending US interest.
It is thus of very HIGH interest for me as a European to know WTF is going on in the US because it may end up killing us all, and even if not we still pay for their shenanigans.
So denying us knowledge of affairs we're *very* involved in is rude.
- My country's military has been in Afghanistan for 20 years because of the US invasion. Nobody knows for how long we will be target of terrorist attacks for that. And as a thank you for all of this, I can't even read your local news sites. I wonder how much the US would be enraged if that situation were reversed?
So who gave the EU the right to be making rules for the entire “WORLD WIDE” web?
If the EU has the right to be making laws for their jurisdiction, then websites in other jurisdictions also have the right to ignore the EU laws and exclude EU members.
They could just leave their website online as is, no need to block it if the laws don't apply to them anyway.
So blocking EU consumers is a perfectly reasonable thing to do, as per the worldview of the EU. You're either in it, or you're not.
Maybe I'm wrong in this assumption, but to me the section you quoted sounds like they're saying "we're not GDPR compliant, so we can't participate in that market right now"; it's not a "fuck you, Europe" kind of thing. But hey, you know what they say about assumptions.
The choice was made in Europe. You reap what you sow.
The option they are looking for is the full repeal of the GDPR. Otherwise they aren't going to bother to do anything.
we don't care about you. You don't bring any revenue. None of our advertisers care to advertise to an EU audience.
Example: And why would a restaurant in Florida care to advertise to someone in Paris? What are the chances that someone in Paris will think "oh I need to eat that burger in XYZ Florida resto?"
(ok my example for Paris-burger-Florida is semi-sarcastic - but true. what are the odds? - what is the cost vs potential benefit?)
It seems a bit odd to not believe there is not only a way to handle this more gracefully but also that Tribune could handle this globally for all of their newspapers.