Berlin is being blackmailed by hackers
bbc.com
bbc.com
Serious question that anyone familiar with the "Verwaltung" (Administration) here in Berlin should ask themselves. Because the fact is, it couldn't have been.
For one thing, how does one analysis and find vulnerabilities in a system? By doing pen-testing but is that legal here? Why didn't someone from the CCC[1] or BSI[2] actually do a pen-test and discover the vulnerability that was used?
Particularly the CCC who like to point fingers and complain about how bad security is. Why didn't they simply do a pen-test and tell the "Verwaltung" about what they found? Probably because they knew that the "Verwaltung" would proceed with legal fixes instead of system fixes, i.e., making hacking even more illegal than it already is.
Meanwhile all the Consultants that the city pays pretended everything was super secure because well ... well because it all Microsoft so it must be secure. We even have the licenses to prove it.
[1] https://en.wikipedia.org/wiki/Chaos_Computer_Club
[2] https://en.wikipedia.org/wiki/Federal_Office_for_Information...
But i am also not sure, what actually happened. Once ya in a system, all is lost.
And the culture around credentials is in my opinion a lost case anyways. I do not know where IT has gone a wrong path. Either security it is super high and you can not do anything (hello bureaucracy) or you can do more, but you become more vulnerable.
Anyways. Data is the new Oil, government said.
I‘m sure that the good guys will catch the badies in the nick of time to prevent a data auction.
Just in time for a good game of tennis and a happy end. Thanks to Hollywood we have nothing to worry about.
I‘m glad _they_‘re not paying and really looking forward to having my private data turn up somewhere I never intended due to _their_ incompetence. I’m sure _they_ can’t help it because of course _they_ aren’t at fault - it was the badies.