this post was submitted on 09 Feb 2025
1012 points (97.0% liked)

Technology

62013 readers
3487 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Anonymous: Trump is making America weaker and we’ll exploit it. The international hacker community is preparing to strike against U.S. infrastructure and calls for public awareness against incoming fascism

you are viewing a single comment's thread
view the rest of the comments
[–] Semi_Hemi_Demigod@lemmy.world 40 points 1 day ago* (last edited 1 day ago) (1 children)

little script kiddies running around

Yeah, they're running around the Treasury Dept right now.

It’s been well known for decades that most government orgs have absolutely abysmal cyber security

Having worked with government agencies and a lot of large private organizations the thing that keeps them mostly secure is the amount of red tape involved with things. Patching a production system requires a teleconference with at least five different people and no one person knows everything.

The idiots without any security experience coming in to "streamline" things will just make the systems even more fragile and insecure.

[–] horse_battery_staple@lemmy.world 4 points 22 hours ago* (last edited 22 hours ago) (1 children)

Known and vetted systems are always the most secure. Until RSA is broken, and then they'll need to update to a quantum resilient standard. Which we've had in the wild for 6 years already and the NIST has officially approved for 2 years.

We're still at least a decade away from a machine with enough qbits to do it. So i feel like we should be fine.

It's the fucking Credit Bureaus, Telecoms, and Energy Companies I worry about. They keep fucking up.

https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms

[–] Semi_Hemi_Demigod@lemmy.world 5 points 22 hours ago (1 children)

Anyone who complies with the NIST standards is in a good place.

The problem is that a lot of places are not in compliance with NIST standards.

I know, I've helped patch them.

[–] horse_battery_staple@lemmy.world 2 points 22 hours ago* (last edited 22 hours ago) (1 children)

Yep, but we've got at least a decade to do it, and when new systems are stood up they "should" be in compliance.

[–] Semi_Hemi_Demigod@lemmy.world 3 points 20 hours ago (1 children)

Based on my experience if we say it needs done in a decade it will never be done.

See also: All the unemployment systems running on FORTRAN

FORTRAN could be said to be security through obscurity though /s