this post was submitted on 09 Feb 2025
1069 points (97.1% liked)

Technology

62005 readers
4379 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Anonymous: Trump is making America weaker and we’ll exploit it. The international hacker community is preparing to strike against U.S. infrastructure and calls for public awareness against incoming fascism

you are viewing a single comment's thread
view the rest of the comments
[–] Semi_Hemi_Demigod@lemmy.world 40 points 1 day ago* (last edited 1 day ago) (1 children)

little script kiddies running around

Yeah, they're running around the Treasury Dept right now.

It’s been well known for decades that most government orgs have absolutely abysmal cyber security

Having worked with government agencies and a lot of large private organizations the thing that keeps them mostly secure is the amount of red tape involved with things. Patching a production system requires a teleconference with at least five different people and no one person knows everything.

The idiots without any security experience coming in to "streamline" things will just make the systems even more fragile and insecure.

[–] horse_battery_staple@lemmy.world 4 points 1 day ago* (last edited 1 day ago) (1 children)

Known and vetted systems are always the most secure. Until RSA is broken, and then they'll need to update to a quantum resilient standard. Which we've had in the wild for 6 years already and the NIST has officially approved for 2 years.

We're still at least a decade away from a machine with enough qbits to do it. So i feel like we should be fine.

It's the fucking Credit Bureaus, Telecoms, and Energy Companies I worry about. They keep fucking up.

https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms

[–] Semi_Hemi_Demigod@lemmy.world 5 points 1 day ago (1 children)

Anyone who complies with the NIST standards is in a good place.

The problem is that a lot of places are not in compliance with NIST standards.

I know, I've helped patch them.

[–] horse_battery_staple@lemmy.world 2 points 1 day ago* (last edited 1 day ago) (1 children)

Yep, but we've got at least a decade to do it, and when new systems are stood up they "should" be in compliance.

[–] Semi_Hemi_Demigod@lemmy.world 3 points 1 day ago (1 children)

Based on my experience if we say it needs done in a decade it will never be done.

See also: All the unemployment systems running on FORTRAN

[–] horse_battery_staple@lemmy.world 2 points 22 hours ago

FORTRAN could be said to be security through obscurity though /s