Top
Best
New

Posted by speckx 1 day ago

Hacker wipes Romania's land registry database(news.risky.biz)
692 points | 392 commentspage 4
DesiLurker 1 day ago|
I know people flip out when they hear the word crypto but this is exactly why you need blockchain. immutable land registry thats public(anonymized).
charcircuit 1 day ago||
Why is deleting the whole database a valid operation? The system should make that impossible.
Tangurena2 1 day ago||
Hackers would do it from the operating system level - stop the database executable, then delete the files used to store the database. Likewise, many organizations store the backups on a network share, where a hacker could delete the files.

Permissions inside the database should be segregated. The credential used by the webserver should not have enough permissions to DROP DATABASE. Just the appropriate selects/updates/inserts.

Likewise, if you are storing backups on the same network (as opposed to a tape backup), network permissions should allow writes/creates but not deletes.

daneel_w 1 day ago||
Why is deleting a row in a table a valid operation? Why is deleting a table in a schema a valid operation? Most likely they had full privileged access to the database.
charcircuit 1 day ago||
>had full privileged access to the database

Why does full access include the ability to delete read only data that should never ever be deleted for the rest of time?

It's like building a self destruct button that ignites the physical records. It's an unnecessary risk to make such a dangerous thing.

daneel_w 1 day ago||
Well, you don't understand databases. Or software.
charcircuit 1 day ago||
I understand that many software projects don't understand the principle of least privilege and make god users that can do anything including deleting everything.
johnnyApplePRNG 1 day ago||
Incompetent bureaucrats strike again.

News at 11.

sebow 1 day ago||
[Fairly off-topic and political]

There's a growing (retarded) perspective, not only here in Romania but in most of the EU, that we must digitalize at all costs; this itself is obviously not a problem, but it usually comes with the removal of the "traditional" options too. The same goes for payments (removal of cash) and basically every aspect of the administration/society where this could be applied. The most recent concrete example for Romania is the mandatory digital signature by ANAF (IRS equivalent) for all companies.

Unlike other regions of the West: NA/WE/rest of the West (SK, JP, etc.), in EE, people (*younger generations, explained below) don't often think about the aspects of confidentiality that much, or if they do, they usually apply it incorrectly (either IRL [filming in public] or online ["I've accepted a draconian TOS that gives the company rights to all of my data, but I haven't actually read any of it, and now I'm invoking my "GDPR rights" against said company."]).

It does not take a genius or a historian to observe that while the older generations do not have this "problem" (they're very skeptical of the gov. [at least in certain aspects], in an almost american fashion — explained by the fact that they've experienced communism), younger generations position themselves in the extreme opposite; they despise the older generations ("boomers") for being luddites and somehow blame them for the gap in civilizational progress between WE and EE. There is a legitimate point here, of course, but it should be noted that the argument is almost always presented in an emotional, overwhelmingly irrational fashion, and almost never includes comparisons between the centralization done by the state in the past [communists] and the new one attempted by current govs [but digitalized]. (This delves into a broader socio-cultural divide between the generations that includes other aspects like religion, traditions, etc.)

The biggest portion of the so-called "IT people" who call for this "digitalization wave" are midwits, "inverse luddites" (they don't care about the implications), and, in smaller numbers, grifters and second-order beneficiaries (on the "digitalization" gov. projects). Obviously, it should be mentioned that, despite progress, nepotism and corruption are still present, and there are cases where gov. contracts are not given to the best candidate.

As a person who's both working in the IT sector and not a boomer (despite the impression of my comment), "we" should be careful about enabling totalitarians in our endeavors."Hackers" is just one reason out of a multitude of other reasons for not abandoning the sacred paper (see the ES+PT incident one year ago).

AdrianB1 1 day ago|
I don't think that most competent IT people are pushing for digital-only systems. The people that I see pushing for digitalization are either clueless politicians or corrupt or incompetent IT people selling snake oil. The sad part is that the snake oil sellers are probably a majority already, so fighting against politicians and snake oil sellers is a tought one.
ExoticPearTree 1 day ago||
[flagged]
nananana9 1 day ago||
Shooting people in the head because they're not wearing a helmet is still a crime.
InsideOutSanta 1 day ago|||
What's even funnier is getting upset about people not wearing helmets the second you hear about an accident, with no idea whether people did or did not wear helmets. All the article says is that "the hacker entered using valid credentials." There's no information about how they got the credentials.
kqp 1 day ago||
Victim blaming is a form of self soothing. If you can get yourself to believe they deserved it, then you avoid feeling that the world is dangerous and you might get hurt too.
dredmorbius 9 hours ago||
There's victim-blaming, and there's gross incompetence.

My own problem with the top-level comment wasn't that it claimed fault on the part of the victims, it's that it didn't substantiate why that claim of fault was applicable in this case.

Multiple use of weak passwords in a critical system isn't acceptable in 2026 (nor has it been for many decades), and yet there's credible evidence (as my own follow-ups in this subthread and my own top-level comments should indicate) that the victims here did contribute significantly to their own harm. For that they should be found accountable. Hosting inherently insecure data systems is gross negligence, quite arguably criminal.

ExoticPearTree 1 day ago||||
You can downvote all you want, but there were actual admin accounts with the password P@ssw0rd. So in your view incompetence should just be ignored because blaming people for lack of common sense will hurt their feelings?
nananana9 5 hours ago|||
Nope. I said that a crime is still a crime, even if the target should know better, in a response to a now flagged comment that was arguing that the criminals were in the right.

You somehow twisted that into "incompetence should just be ignored because blaming people for lack of common sense will hurt their feelings" which is such a ridiculous strawman that you're either arguing in bad faith or you've completely lost all ability to do even the most basic of reading and reasoning.

dredmorbius 1 day ago|||
In this specific case? Documented?

If so, point to references. Otherwise your original comment reads as unsubstantive. Tropes and cliches may have value because they're often true, but if true, in this case, then share that fact and not the trope alone.

ExoticPearTree 1 day ago||
https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...

and click on the links in the article - they are screenshots from inside the system.

Like this one for example: https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...

To answer your question: yes, in this specific case, documented.

dredmorbius 1 day ago||
Sincerely, thank you.

Your initial comment would have been far more substantial, and probably much better received, with these additions.

ajsnigrutin 1 day ago|||
But you still get fined if you don't wear a helmet

In an ideal world, even before you crash your motorcycle and hit your head somewhere, forcing you to start wearing it

busterarm 1 day ago||
I'll never forget this one video. A cyclist riding with a helmet on was doing everything proper -- helmeted, obeying traffic laws, riding in the proper part of the road...

Then a city bus passes them far too close. The passenger side mirror of the bus catches the rider's helmet and speeds off...carrying the cyclist off of their bike and dangling by their helmet at speed...

alt227 1 day ago|||
Freak accidents occur everywhere. Helmets save a lot more lives then causee deaths overall.
ajsnigrutin 8 hours ago||
Yep, same with seatbelts... a lot of broken ribs, etc. and people complaining.

If you crashed so hard, the belt broke your ribs, without the seatbelt, you'd be dead right now, head first through the windshield. I mean sure, you wouldn't be complaining about broken ribs, but yeah...

busterarm 8 hours ago||
I wasn't even complaining about either. I use both. I just think it's pointless to bitch about other people gambling with their own lives.

If someone wants to win a Darwin award, let them. Because you can just as easily do all the right things and get taken out regardless.

dgellow 1 day ago|||
I will never forget your description of the video :(
hnlmorg 1 day ago|||
Do you know that this system was making fundamental security faux pas or are you assuming the reductive argument where determined enough hackers couldn’t break any system with built and maintained by diligent engineers?
mihaic 1 day ago|||
Romanian here. There really were admin accounts with the password Passw0rd, created so that some incompetent political apointees could browse the data.
BobBagwill 1 day ago|||
Gee, I didn't know Moscul is helping the Romanian government too! :-)
vkou 1 day ago|||
I'm a quarter Romanian on my step-mother's side, and I too can confirm that the password was Passw0rd.
ExoticPearTree 1 day ago|||
> Do you know that this system was making fundamental security faux pas or are you assuming the reductive argument where determined enough hackers couldn’t break any system with built and maintained by diligent engineers?

You should take a closer look at the screenshots posted by the hacker: entire systems and network devices with the password P@ssw0rd for the admin user. Now you tell me.

dredmorbius 1 day ago||
Your comment could have been shortened to:

Take a closer look at the screenshots posted by the hacker: entire systems and network devices with the password P@ssw0rd for the admin user.

Linking those would be bonus.

<https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...>

otabdeveloper4 1 day ago||
If you're using passwords as an authentication methods then you've already lost.
DigitResort 1 day ago||
[flagged]
c7b 1 day ago||
[flagged]
codedokode 1 day ago||
So that 50% attack results in someone taking all the land? No thanks.

It is a poor idea to use blockchain for government registries. If you want transparency, simply publish signed daily updates and that's enough. Just use simple DB with backups, and optionally, a printer printing changes on a paper.

consp 1 day ago|||
Merkel tree audit log of the data, the poor man's Blockchain, works fine and good enough. Now you have a db and you can claim to use a blockchain for pr reasons.
c7b 1 day ago||||
2/3 attack. Read up on BFT.
codedokode 1 day ago||
It doesn't matter, it's a dumb idea anyway because there is a central authority managing the land registry and there is no need for anyone else to be involved.

Also, SQL database is much more convenient to use, it has query language and indices unlike a blockchain.

c7b 1 day ago||
You can put an index on your blockchain DB, what are you talking? Every node can manage it as it pleases (within the limits of the consensus algorithm).

Yes, if you have a centralized model you don't need it. Just saying that this incident is the exact risk a blockchain is meant to mitigate through redundancy. You can say you don't care about this risk, but it doesn't change the truth of the statement.

FeepingCreature 1 day ago||||
Yeah, the overwhelming majority of the benefit of blockchain here is just gotten by making the data public and signed.

Now you may argue "that is a blockchain, not every blockchain is associated with a shitcoin" but to be frank that ship has sailed, if you wanted to defend that you'd have had to do a lot more work over the past decade.

Ekaros 1 day ago|||
Which could easily be solved by just making data publicly accessible. Actually I see no reason why you shouldn't be able to download land registry say every month. Same actually goes for any stock ownership in companies over certain threshold.
c7b 1 day ago||||
That is what I'm saying. And you may be right, but the security guarantees are math and math is patient. If people decide to ignore it today, it'll still be true any time they decide to take another look.
protocolture 21 hours ago|||
>Now you may argue "that is a blockchain, not every blockchain is associated with a shitcoin" but to be frank that ship has sailed, if you wanted to defend that you'd have had to do a lot more work over the past decade.

What do you mean by "More Work" here?

There were plenty of tests and pilots of systems like that described. Dual goals of reducing the cost of transferring property and publicly attesting all current ownership. Real lawyers and real lawmakers developed proposals to integrate these sort of services with current public land registries.

The issue as far as I see it isnt the "work" its the "antiwork". If you want to learn about land sale nft pilots you literally have to put -metaverse into the google search to weed out the metaverse nonsense. Theres just too much noise around blockchain for even the best signal to penetrate. The stupid monkey nft guys really fucked the whole space. Probably take another decade to dig out all the toxic waste from blockchains reputation.

mschuster91 1 day ago|||
> It is a poor idea to use blockchain for government registries. If you want transparency, simply publish signed daily updates and that's enough.

A blockchain is essentially that, just with the daily update that's being signed also including the signature and hash of the previous day.

Blockchain as a technology is actually useful here. It does not mean automatically that blocks have to be mined by third parties, although pseudocurrencies have gone that route for decentralization reasons.

codedokode 1 day ago||
Blockchain is unnecessary complicated, for example, it has mining, rewards for those who add new records, even VM and scripts and all of these are not needed for a government registry. I do not need scripts within a land registry.
homakov 1 day ago|||
> Blockchain is unnecessary complicated, for example, it has mining

depends on configuration, you can make any traditional web service replicated (replication is one and only thing that protects data in decentralized ledger, same as DNA is stored in every cell) using something like CometBFT on top. Mining/PoS or VM - all optional.

c7b 1 day ago|||
Clearly, you would scope the features and choose implementation options so that it makes sense for the use case. Mining (ie PoW and/or Nakamoto consensus) is clearly inferior to any deterministic consensus here. A cryptocurrency isn't necessary and would be a distraction. But at least some limited programmability could make sense (eg for escrow).
mjburgess 1 day ago|||
If they deleted the blockchain db from the nodes, this is still lost.

Blockchain doesn't have anything esp. to do with data loss. It solves exactly one problem which is distributed double spending in accounting ledgers.

c7b 1 day ago|||
A blockchain solves the problem of consensus under Byzantine faults. Payments are an incidental use case, and not even a good one because managing payments including avoiding double spending can be achieved with a weaker primitive than consensus.
drptech 1 day ago|||
[dead]
inigyou 1 day ago|||
I suppose the idea could be that you have several different institutions holding the same data, which they know is valid because of the Blockchain.
codedokode 1 day ago||
No. Blockchain is made for managing transactions between untrusted parties. In case with a land, there is an authority managing the registry, so a standard relational DB (with optional digital signatures) is the bets option. Why someone wants to use a tool, not good for a specific purpose, for that exact purpose?
inigyou 12 hours ago||
"X is made for Y" is inside-the-box thinking
bilekas 1 day ago||
I would be less comfortable with my land registry tied to a blockchain, as soon as I lose it (who is much more likely to) it's impossible to get my land back.

What's wrong with paper records backup up a digital record and audit trail. This all seems like a solution for a non-problem to me.

c7b 1 day ago||
A blockchain isn't stopping you from doing any of those things, if anything it's facilitating different backup models by different parties. A paper record is so much more susceptible to various kinds of risks, adversarial and otherwise. I recommend to look past the hype or hate at the technology. A blockchain is the logical extreme of where you end up when you think about how to sync backups, and you recognize that it comes with certain mathematical limitations on how much disruption you can handle.
margalabargala 1 day ago||
> A blockchain is the logical extreme of where you end up when you think about how to sync backups

It's not. Blockchains are only eventually consistent among nodes. They're designed for synced backups among adversarial peers.

There's no reason for a government agency to use one internally. There are better ways to sync backups when the people with access to make updates are also authorized to do so.

c7b 1 day ago||
Internally, you don't need it, agreed. But that is centralization risk exemplified in this incident. Which isn't necessary. Every notary could be a node. It would be a lot more resilient, and it would look a lot like a blockchain (not necessarily with a crypto currency though) if you do it properly.
margalabargala 1 day ago|||
You can have decentralization without blockchain. A defining feature of blockchain is that each node depends on the precise ordering of prior nodes which is a huge liability if you have network disruptions, etc, in a bureaucracy.

A git repo with cryptographically signed commits solves all the same problems without the headache.

c7b 1 day ago|||
Agreed that you don't need total ordering and hence consensus for pure asset transfers. But if you want to make any changes at all, like updating the list of nodes, you do. So in practice, you do need it. Every other proposal will fall short in a critical and avoidable way. Amending your git proposal with the necessary parts will turn it into a blockchain.
margalabargala 1 day ago||
Disagree. We're talking real estate here. The time between transactions is months to years, not seconds to minutes. A git history will work fine. If there are racing transactions against the same piece of real estate, that's probably fraud, not something that should be automatically resolved.
c7b 1 day ago||
git as-is is completely unfit for purpose and a huge security risk for this use case, because it uses MD5, which is no longer collision-resistant.

If your proposal is 'something like git, with a few modifications to make it suitable for this use case', then that's exactly what I'm proposing. What you will need, once you've considered all requirements to the best extent feasible, will be a blockchain. Eg you do need the ability to make protocol updates, no matter the time scale of transactions.

margalabargala 1 day ago||
> git as-is is completely unfit for purpose and a huge security risk for this use case, because it uses MD5, which is no longer collision-resistant.

Firstly, git does not use MD5. It uses SHA1.

Secondly, since 2017 git has shipped with an implementation of SHA1 (sha1dc) that detects the collision attack you describe, which for this use case renders it a non-issue.

Thirdly, git supports `git init --object-format=sha256` which removes the whole issue for anyone who cares to do so.

I think git as-is solves the problem nicely. The only additional value blockchain provides is the ability for someone to point at it and say "look! A use for blockchain exists!" which isn't worth the downsides it'll bring.

homakov 1 day ago|||
You can't do any real money/real estate transactions without canonical order (chain of events). that's why git analogy is not applicable here. You'd need "main" branch to be canonically finalized for each and every participant.
margalabargala 23 hours ago||
What? Sure you can. All you need is confidence in the current owner. You don't need the whole history. Can you imagine the poor store clerk trying to say "sorry sir I can't accept that $20 bill unless you can name every prior owner in order".

Not sure if you're being deliberately obtuse here but this isn't an issue with the cadence of real estate transactions. Real estate ledgers do not need to support HFT.

homakov 3 hours ago||
Never said you need to store the whole history at all times, i said it must be established in canonical way. Storing latest state is just fine. Event Sourcing works this way too, and allows caching recent state.
codedokode 1 day ago|||
If every notary is a node, you need some mechanism to ensure they perform only legitimate transactions and constantly monitor them. It is easier to just have a central authority.
c7b 1 day ago||
You need that anyway. It's not technology that's stopping notaries from falsifying transactions in the current system.
spwa4 1 day ago||
Amateurs. Everybody knows you should never wipe databases. You should install a cronjob that makes a random, unrecoverable change on a regular (but random) basis.
m0llusk 1 day ago||
Seems like property ownership histories could be one of the few good applications of blockchain technology.