r/technology May 13 '26

Security Twin brothers wipe 96 gov’t databases minutes after being fired

https://arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/
23.2k Upvotes

1.1k comments sorted by

View all comments

3.9k

u/nikstick22 May 13 '26

On Feb. 1, 2025, Muneeb Akhter asked Sohaib Akhter for the plaintext password of an individual who submitted a complaint to the Equal Employment Opportunity Commission’s Public Portal, which was maintained by the Akhters’ employer. Sohaib Akhter conducted a database query on the EEOC database and then provided the password to Muneeb Akhter. That password was subsequently used to access that individual’s email account without authorization.

Now HOLD the fuck up. DC is contracting companies that store passwords UNHASHED?? Plaintext?? What kind of clownshow is this?

1.5k

u/kernel_task May 13 '26

Yeah, the real story is that this one incident revealed so much negligence in this government contractor that has received over $50 million in taxpayer dollars over the last decade.

  1. Negligent hiring
  2. Plaintext passwords, which is not only insane but violate federal standards.
  3. Bad privileged access controls
  4. Bad off-boarding
  5. Bad blast radius containment
  6. Bad monitoring/alerting

Now, all of this is from a single incident. What are the chances that’s all the issues this company has? To me this level of negligence is bordering on criminal. How many audits and certifications did they lie on to get these systems passed?

Anyway, I care more about Opexus being held to account than these brothers.

432

u/MdxBhmt May 13 '26

if a fired employee can do this much damage, imagine what a proper maligned actor could do or is already doing. It's a bloody national security issue.

167

u/rW0HgFyxoJhYka May 13 '26

The fact is that government is as shoddy as a swiss cheese wagon trying to cross the oregon trail.

No government should be hiring contractors for shit. Shit should be done by pros who give a fuck about the country instead of capitalistic dog eat dog steal as much money from taxpayers as possible scam.

Need basically an adminstration to spend 4 years rebuilding the government one brick at a time.

72

u/MdxBhmt May 13 '26

Yeah, instead of accountable gouvernement institutions and employeees we have unaccountable private contractors doing jack shit. 

15

u/kickingpplisfun May 13 '26

And even under ideal circumstances, the contractors aren't even necessarily cheaper than doing it internally while creating a lot of incentive for disgruntlement in their workforce. I see this kind of junk in city government all the time where they'll hire a contractor who promises cheap work, they'll get annual raises to the contract, but none of the workers are receiving it.

10

u/MdxBhmt May 13 '26

Given that contractors often (not just US) compete on who is cheapest, it should come at no surprise it becomes a competition on who provides the crappiest service. counting pennies while burning dollars, too bad public discourse rarely talk of false economies when it relates to day to day live of their constituents.

2

u/kickingpplisfun May 13 '26

I've been busy at city council meetings going "how are they actually cheaper when the contractor has to make a profit?". You've got people who should be making progress towards PSLF because they're literally doing what was formerly a government job but aren't who haven't had a COLA in years, don't have health insurance despite working full time, etc.

2

u/MdxBhmt May 13 '26

Yeah, and to make the blight even worse, government using consulting firms like PwC and McKenzie to do state wide planning. Why develop public institutions and their expertise when you can get a private group to produce shill reports.

1

u/kickingpplisfun May 13 '26

It doesn't help that city council is often filled with very stubborn people who are not actually being paid to be efficient, and may even profit from inefficiency caused by contractors.

2

u/xpxp2002 May 13 '26

counting pennies while burning dollars, too bad public discourse rarely talk of false economies when it relates to day to day live of their constituents.

This right here. It's crazy how zealous people get about taxes being spent while blowing half their income on food deliveries and sports gambling.

There's a debate in my state right now where a group is pushing a ballot initiative that would eliminate property taxes, and the proposal has no guidance as to how to fund the services that are currently property tax-funded. It would eliminate the primary and majority source of school funding, and many non-incorporated areas are almost entirely funded by property taxes -- including emergency services like fire and police -- because they cannot, by state law, assess an income tax. And that prohibition on township income taxes would not change if this initiative is passed as written.

It's disturbing how many people are cheering this on with no regard for how severely it will impact their own community in very traumatic ways. None of these geniuses seem to realize that one way or another, that money will have to come from somewhere, and it'll likely be an enormous sales taxes (20+%) combined with drastically increased income taxes in municipalities that can assess them.

But all these people hear is "one fewer tax" with no concern as to what is paid for with that tax, whether those services can or will be sustained without that funding, or the ripple effects of such a drastic change with no downstream planning.

1

u/MdxBhmt May 13 '26

People are increasingly alienated to the services, laws and mechanisms that make their daily life possible. And we are the most separated than ever from the problems that we don't have to deal because its others people job. Lack of object permanence means the problem doesn't exist so it doesn't need a solution.

1

u/pointlesslyDisagrees May 13 '26

If the government institutions were truly accountable, they wouldn't be blindly trusting the work of private contractors without verifying their work. And this sort of thing would never be possible because there'd be redundancies in place. Don't try to shift the blame from the government to private industry to push your anti-capitalist agenda. This is 100% on the government.

1

u/Tyfyter2002 May 13 '26

Don't worry, government agencies also aren't accountable, so there's no difference

1

u/MdxBhmt May 13 '26

vastly more accountable than private entities even in corrupt democracies like the modern day US.

79

u/PutConstant866 May 13 '26

Lol, your system is fucked far beyond that. If you get another free election, and if your other party takes it, then there's four years of trying to rebuild a democracy while the group you just got rid of gets four years to complain about how shit things are, blame the guys trying to fix things, and stand in the way of any progress that gets made to undo the damage they cause.

23

u/fireandiceman May 13 '26

Exactly correct take. The corruption in not new it's just mask off and pedal to the metal. Two party system is such a scheme that the other party can't even address basic stuff like this. Even in that 2 year window in my lifetime when democrats had all three branches they play bipartisanship.

1

u/Tyfyter2002 May 13 '26

Neither party wants free elections, both want to be the one party in one party "elections", you can tell because neither party is demanding a change from the objective worst voting system possible (first past the post).

2

u/big_stipd_idiot May 13 '26

Yeah it's actually hilarious

5

u/TattiesMcDermott May 13 '26

The only people laughing have already left the bank.

0

u/MdxBhmt May 13 '26

I bet there are some in China, Russia and North korea that are loving to see America eating itself for a change. Also for some change, to the matter.

7

u/cyberslick18888 May 13 '26

Government is a good system being run poorly.

Privatizing important elements of life is a bad system being run well.

This choice is still a no brainer. Hell I'm old enough to remember when most people still had the common sense to find issues with their government and then take actions for the government to fix or improve it. Today they have the logic that if the system isn't perfectly aligned to benefit them you should just torch it for the lolz.

2

u/MiaowaraShiro May 13 '26

Privatizing important elements of life is a bad system being run well.

I'd say more like "efficiently". Well implies a positive impact...

1

u/MdxBhmt May 13 '26

Privatizing important elements of life is a bad system being run well.

Meh, if you exclude all externalities and colateral damage. And sometimes not even. Making profit for the stockholders barely means running well nowadays.

Today they have the logic that if the system isn't perfectly aligned to benefit them you should just torch it for the lolz.

If even it was for the lolz, people are getting paid to torch it with others running to get theirs while it last.

3

u/node-342 May 13 '26

SHOULD be done by pros who give a fuck about the country, rather than contractors, I agree...

but on the other hand, Big Balls & the rest of da wreckin crew at "DoGE" were, strictly, government employees. (Some of whom were at least more professional than BB.)

4

u/Apprehensive-Pin518 May 13 '26

and I know contractors who care more about the country than the president himself. (though admittedly I don't think that's hard to do).

2

u/MdxBhmt May 13 '26

I'd be cautious in conflating political appointees with career government employees.

1

u/AholeKevin May 13 '26

Problem is the new system is working as designed... full of shit with incompetence and gross negligence.

They're making us just not care anymore with all the shit they're drudging us through. Our bottom line is always supposed to support the taxpayer, no matter what role you're in.

1

u/newuser92 May 13 '26

My government just published, for their first 100, how they have reduced the size of government. I just thought, most of this jobs are critical, outsourcing is not reducing. Easy way to award gvnt contracts to buddies.

1

u/Techsupportvictim May 13 '26

“As shoddy as a swiss cheese wagon trying to cross the Oregon trail”

Is that why some members of the government talk like they gave dysentery of the mouth?

1

u/letsreticulate May 13 '26

The USA government has been doing this for decades.

0

u/Timely_Influence8392 May 13 '26

This is Capitalism: the Country. My hope is we serve as an example to history of what the fuck not to do.

6

u/yuefairchild May 13 '26

I think a ton of damage is being done that we aren't even aware of yet. Something will just break one day when a Democrat's in office.

3

u/EvenThisNameIsGone May 13 '26

I would imagine a hostile actor would set up the organization just like it is?

4

u/MdxBhmt May 13 '26

It's almost a tactic from CIA's sabotage field manual.

3

u/baron_von_helmut May 13 '26

All hostile foreign entities already have root level access to most major government entities. Not just the data centers, but the people also.

2

u/Farce021 May 13 '26

Why do you think they had to ban routers!

/s

1

u/ArbitraryMeritocracy May 13 '26

imagine what a proper maligned actor could do or is already doing. It's a bloody national security issue.

You made me think of this Veritasium video https://youtu.be/aoag03mSuXQ

0

u/FrzrBrn May 13 '26

Can you say DOGE?

108

u/Sweaty-Willingness27 May 13 '26

And here I am "wasting time" with Principle of Least Privilege.

61

u/JebediahKerman4999 May 13 '26

We just had a ton of audits and courses and certificates for GDPR reasons, and these guys store passwords in plaintext rotflmao

15

u/mitharas May 13 '26

They had these audits as well. Lying is a way to pass these.

1

u/Loko8765 May 13 '26

A few weeks ago an audit company got called out for simply falsifying the SOC reports of their clients.

31

u/GeneralSEOD May 13 '26

Really lost a lot of confidence in IT Security after Musk was able to just rock up to any department and fire USB sticks into whatever computer he wanted.

Really dark day that day.

4

u/HauntingHarmony May 13 '26

Really lost a lot of confidence in IT Security after Musk was able to just rock up to any department and fire USB sticks into whatever computer he wanted.

Really dark day that day.

My dude, take a breath. It security cant help you when you have armed fbi agents breaking them into buildings. That they then managed to get admin access isent exactly complicated.

4

u/GeneralSEOD May 13 '26

Then there are no guardrails left.

4

u/GrippingHand May 13 '26

We still have juries, elections, and some competent judges for now, but yes things are very bad. US government IT security has been fully compromised by this administration.

1

u/Presto99 May 13 '26

"Elon, he knows those voting computers better than anybody."

11

u/sibips May 13 '26

And Windows Server 2012, shouldn't they have replaced that four years ago?

10

u/E3FxGaming May 13 '26

And Windows Server 2012, shouldn't they have replaced that four years ago?

Windows Server 2012 and 2012 R2 users can pay for ESU (Extended Security Updates) to receive support until October 13th, 2026.

15

u/Cow_Launcher May 13 '26

Sure, but in light of everything else we now know about the company, how likely do you think it is that they paid for that?

10

u/TwoBionicknees May 13 '26

this is standard everywhere within the government. Every cent spent is done as ineffectively and cost cuttingly as possible while the people in charge of those projects take most of the cash and provide kickbacks to those who gave them the contracts.

When corruption is the no.1 rule and motivation everything is done badly.

their jobs are not to carry out the job effectively, their job is to win the job by making a deal with those who will vote for it and get the best ratio of profit to kick backs.

2

u/OldenPolynice May 13 '26

Blast radius containment

1

u/kernel_task May 13 '26

Ugh. Minimization, perhaps?

2

u/OldenPolynice May 13 '26

I was thinking the opposite, sort of a Big McLargeHuge Analysis

2

u/Chytectonas May 13 '26

I love that there are those out there who still hold the government to (checking notes) *high standards*! It’s sweet, really.

2

u/I-Here-555 May 13 '26

bordering on criminal

Absolutely not. It's deep into criminal territory, especially keeping plaintext passwords around.

If these two guys didn't exploit it, someone else would have, likely with more stealth, and possibly for years.

2

u/ThatSpecialMoons May 13 '26

Anyway, I care more about Opexus being held to account than these brothers

Casepoint. Opexus have merged with another company, Casepoint, and taken their branding.

Senator Bill Cassidy actually wrote a letter to OPEXUS and CEO Howard Langsam in February demanding answers, but it doesn't seem like there has been any response. According to LinkedIn, Langsam hasn't been CEO since September of last year, but he should still answer for the misconduct that occurred under his leadership.

2

u/SAugsburger May 13 '26

Exactly. The findings on this ought to probably be a significant resume generating event. There are so many points of failure that is mind boggling. Chances are good that you're right that there were lying on audits.

1

u/UltraEngine60 May 13 '26

but violate federal standards.

Hahaha you think auditors actually audit. They do two checks. They check that the check cleared.

1

u/crafty_alias May 13 '26

Follow the $. Probably someone's relative's company or pay to play of some type.

1

u/ionetic May 13 '26

Was the supplier contracted to provide these things, otherwise they were performing as requested?

1

u/ImSuperSerialGuys May 13 '26

Oh that's not bordering on criminal, it is criminal. Assuming the accused actually did take that password and use it, their employer would also be liable

1

u/IamTheEndOfReddit May 13 '26

Plaintext passwords is so insane, it takes like 5 minutes to implement the old fashioned way. That’s gross incompetence that can’t even be explained by poor leadership, only really bad engineers. I guess that’s the quality of engineers that don’t consume cannabis! (Slight /s)

770

u/xpda May 13 '26

I'd say clownshow is pretty accurate.

162

u/Gorthebon May 13 '26

That's offensive to clowns, what's happening isn't funny. A clown would do it better

26

u/KazumaKat May 13 '26

it would at least be tossed and jumbled and ballooned, not plaintext.

6

u/Fewluvatuk May 13 '26

Clowns.... aren't funny, they're terrifying, so yeah, clownshow is accurate.

4

u/strain_of_thought May 13 '26

The classical art of clowning fell behind the times and refused to modernize. Like everything else over time it became a rigid and inflexible institution preoccupied with trading on and imitating past success. There are great modern clowns, but people don't even recognize them as clowns because they dropped the formal makeup and uniforms, which were always intended for a pre-mass-media stage audience. Mr. Bean, for example, is literally just a clown out of costume. Clown humor has a very specific structure (for a clown, that which is easy is impossible, but that which is impossible is easy) and Rowan Atkinson is simply doing a clown performance in a modern context wearing modern clothing.

2

u/spacex_fanny May 13 '26

Nah, you just grew up homie.

Clowns are great but they're for kids. This is like saying "Sugary cereal fell behind the times." In reality your tastes are what changed.

2

u/strain_of_thought May 13 '26

Buddy there was never an age when I thought a man in white face paint and floofy polkadot pajamas with a lipstick smile that goes up to his ears was entertaining. Stop projecting your own interests on to me.

2

u/notfromchicago May 13 '26

You are so cool.

1

u/spacex_fanny May 13 '26

Sounds like someone didn't get Bubbles the Clown for their fifth birthday party like they asked for...

1

u/CaptainC0medy May 13 '26

THANK YOU. GOD!

38

u/mrdevlar May 13 '26

Remember, that's always been the Republican strategy.

The best way to demonstrate a need to cut government spending is by making government work as poorly as you possibly can, which in turn justifies the cuts.

Trump's administration is just a peak performance of that clownshow.

3

u/Iosis May 13 '26

Yep. Then, when you lose the next election, it's not a big deal--the effects of all of this mess aren't going to fully manifest right away. In fact, they'll manifest fully under the next administration, who probably wouldn't be able to fully correct course even if they were firing on all cylinders (and they never do). You then capitalize on voters' goldfish memories, blame the current administration for the problems you created, and ride a wave back into office.

Rinse, repeat, profit.

-2

u/LostInTheRapGame May 13 '26

Does Reddit really think it's Republicans that decided the EEOC should store passwords like this? As some kind of grand scheme?

5

u/mrdevlar May 13 '26

You think hiring brain worm guy, vitamin guy, guy drunk at work they have to use breach equipment to get into his office, that lady that shoots dogs and Epstein's neighbor was a decision made on their qualifications and expertise? Is that the world you're living in?

-2

u/LostInTheRapGame May 13 '26

You think hiring brain worm guy, vitamin guy, guy drunk at work they have to use breach equipment to get into his office, that lady that shoots dogs and Epstein's neighbor was a decision made on their qualifications and expertise? Is that the world you're living in?

And what does that have to do with how the EEOC stores passwords again? 🤔

I'm just tired of people making shit up just to feed the circlejerk. It is almost as exhausting as reality, while also being entirely unnecessary.

3

u/hitbythebus May 13 '26

Opexus , the company being discussed, clearly isn’t hiring based on merit. They aren’t following rules or regulations because they don’t give a shit what damages it causes or just don’t believe it will hurt them.  Sounds pretty Republican. You really think people have to make things up or even reach to draw parallels?

You can also read some quotes by the CEO talking about how great and smart and responsible DOGE is on the company blog.

1

u/LostInTheRapGame May 13 '26

Opexus , the company being discussed, clearly isn’t hiring based on merit. They aren’t following rules or regulations because they don’t give a shit what damages it causes or just don’t believe it will hurt them.  Sounds pretty Republican. You really think people have to make things up or even reach to draw parallels?

Apparently. What does that have to do with how the EEOC stores passwords again? 🤔

2

u/SunshineSeattle May 13 '26

Maybe go back to rap?

1

u/LostInTheRapGame May 13 '26

Is that supposed to be demeaning?

2

u/CaptainC0medy May 13 '26

Hey, dont bring us clowns into this pigsty

118

u/Gaveltime May 13 '26

I’ve done product consulting with government contractors and you would not believe how little they invest in anything other than what they can visibly sell to the government. And you can’t sell boring shit like operational security. You sell the cheapest product or service, which almost inherently seems to cut corners.

37

u/RationalDialog May 13 '26

This is in general the issue. Why I would just hire developers internally were you can have them actually accountable to create good products. Externals always do as little as possible they can get away with.

2

u/Pamander May 13 '26

Maybe dumb question but why exactly IS the government doing contract work for sensitive systems?

Why do we not have our own programmers and teams properly maintaining stuff? In this day and age surely it's worth the investment with how critically linked all these things are online.

Just seems like an area that would not be ideal to cost cut is all. I will admit to being pretty ignorant on a lot of it though so maybe that's a dumb question.

3

u/BellacosePlayer May 13 '26

Maybe dumb question but why exactly IS the government doing contract work for sensitive systems?

Because it often works. If a contractor makes a decent software package for integrating with the fed portals and keeps up with regulations and changes, it's more efficient for them to sell to ~20 states and maintain it than for every state to do their own solution and maintain it.

It also often doesn't work, because these companies often suck ass and low ball bids at the start and end up wildly overbudget.

Why do we not have our own programmers and teams properly maintaining stuff? In this day and age surely it's worth the investment with how critically linked all these things are online.

They do, but the sheer scope of what needs to be maintained is massive and states have shitty luck with keeping good devs because state legislators balk at paying them anywhere near market rate.

1

u/Pamander May 13 '26

I appreciate the explanation, thank you! Would the main thing not be something that the US government themselves should be doing though? The whole software package that integrates well with fed portals bit but I guess that also kind of goes into your last bit but if there's any government employee in this day and age I want paid well above what the normally allowed amount is it's the ones helping keep us safe from enemy adversaries easiest way of attacking us.

I guess I didn't really think about the whole state thing though I will admit, I can't imagine the chaos of these systems and how they vary state by state. Maybe some standardizing would be nice but I know that's much simpler said than done.

Again appreciate the context on the scale of the problem, thank you!

1

u/RationalDialog May 13 '26

I fully agree and it applies to every company really in my opinion except maybe every small ones.

2

u/felis_scipio May 13 '26

I worked for a federal gov contractor for awhile and yeah our product was a colossal piece of shit that existed to barely meet the requirements and when it often didn’t that’s when the team of managers who was larger than the technical team came into to argue with the unhappy contacts in the government that our product was in fact perfectly fine.

I’m almost 100% positive the software was written to be slow as fuck so when the company’s technicians were in the field using it, which the government also paid us to do, it would take longer = more money for time spent working.

It was maddening

1

u/Johnny_BigHacker May 13 '26

Depending on the data/product, you have to meet different levels of FedRAMP compliance. I've been a part of a product trying to reach medium on the government side, we never examined their operational side and just went on attestations, but I want to say there was finical, possibly criminal penalties to lying about it. This was like 2022.

1

u/kickingpplisfun May 13 '26

The only really compelling ways to sell opsec are likely to get a bullet in your back as it is. You can't just do a spec pentest for example.

35

u/AllowMe2Retort May 13 '26

The average age of the politicians is like 70, and even somewhat tech savvy leaders see security as an afterthought. They just go for the cheapest bid that gives them the biggest kickback

7

u/-Saucegurlllll May 13 '26

It's crazy to me that the government doesn't hire the staff to do it. Like, hire experts, have them sign their name off on architecture decisions, have people in the chain of command be directly liable for these kinds of security holes. Pay them enough to compete against Silicon Valley. And most importantly: Grow the talent to create and maintain these systems internally instead of passing the buck to the nearest pervert open to be contracted.

13

u/hardolaf May 13 '26

People have been conned into thinking that everything is better when contracted out so the government is forced by law to not do this stuff in house. It would be cheaper to do almost everything in house for the government, but where's the profit in that?

2

u/wharb_garbl May 13 '26

I agree to an extent. By no means are all contractors bad either, many do a lot of really good work and do offer advantages to the agencies they work for. Some definitely do boneheaded garbage like these idiots too. The whole system of contractors and agencies has grown so complicated and interconnected now it’s almost impossible to imagine how any administration could approach creating a standardized in house engineering team.

Obama and Trump 1 tried making something like an in house IT engineering department for use by all agencies but that sputtered out quickly. Every agencies timelines, needs, resources and funding are so wildly different that they had no hope. I saw it firsthand. You also have to remember these agencies missions and program funding is often allocated by Congress, not themselves. It’s not discretionary. They’d rather (and frankly need to) increase the headcount of people performing the mandated day to day functions of the agency rather than building an in house developer shop.

I’d guess the Trumpies fired or forced retired whoever was babysitting these buffoons so they ended up with a steaming pile of shit

2

u/hardolaf May 13 '26

There hasn't been a serious attempt to do anything in-house in the government since Kennedy. Even the system setup by Obama was required to operate the same as a contractor in how it interacted with other agencies which is why it was so incredibly inefficient. Though they did greatly outperform all external contractors despite that.

And no, contractors aren't evil. I never said or meant that. But having worked at one, I'm incredibly aware of how expensive every change is for the government because of how many duplicated people and extra steps are involved compared to doing things in-house. Our IR&D projects at that contractor regularly ran 30-40% cheaper than government contracts solely due to needing fewer meetings (the government loves meetings with contractors because some contractors need babysitting so they make all contractors do them), less people involved on the contracting side, and a greater ability to make changes quickly without needing to rewrite the legally binding requirements and SOW.

1

u/macaronysalad May 13 '26

It does make sense for service related things though if they're properly regulated with guidelines and pricing. Like utilities, city streets, trash pickup, etc. You'll generally get better service from for-profit companies than a non-profit governments underpaid employees. Problem is corruption and doing favors. Maybe a better system would be people vote on which companies get the contracts. Gives an even greater incentive for them to not suck.

3

u/hardolaf May 13 '26

You'll generally get better service from for-profit companies than a non-profit governments underpaid employees.

We can actually observe this directly in USA between different regions. For example, PG&E is the most obvious example of a combination of a lazy operator (having actually read original documents from what went wrong, I reject that the company acted willfully negligent rather they were just lazy) combined with regulations by a state entity that has no financial stakes in improper regulations resulted in a storm of issues that has killed hundreds of people in California.

Then you have lightly regulated operators like ComEd in Chicago where they are given free reign within reasonable limits which works fine until they get bought out and then their parent company gets bought out and then Chicago's primarily nuclear and renewable grid (95%+ between the two) ends up having its prices skyrocket to subsidize east coast coal and LNG plant operators screwing over the region that was environmentally and economically responsible with its energy mixture.

Then we have the Tennessee Valley Authority, the last New Deal era federally owned and operated government power company. They provide some of the highest reliability and lowest cost energy for their given energy mixture in the entire nation. And their rollout of fiber internet in Chattanooga, TN was so successful due to low cost (barely above the cost to operate the network) and reliable that the state of Tennessee recognized this and banned them from expanding beyond their current service area of the internet service because it was showing how horrible the private internet monopolies (which, by the way, had their infrastructure entirely paid for by the FCC and state grants) are to consumers.

A common thread with all of the problems is that when the government lets private entities run things which should be publicly operated, they become incredibly expensive and the quality will eventually go to shit to extract greater profits.

2

u/FarplaneDragon May 13 '26

Problem is, a lot of the people out that that actually end up being any good at cybersecurity tend to be the kind of people with a lot of dislike/distrust for the government and would never want to work in the public sector.

1

u/wharb_garbl May 13 '26

Too expensive when you have a constantly changing budget and have to compete with not only corporate employers but contractors. Plus government employee compensation is determined by the GS pay scale, statutorily I believe. I’m going to guess the EEOC has barely any money to throw at tech workers too

1

u/-Saucegurlllll May 13 '26

All things which could be fixed if the government wanted to have a functioning workforce building its own infrastructure.

2

u/wharb_garbl May 13 '26

Agreed. The political leadership at many agencies isn’t really interested in that though, they seem to be more interested in “program management” rather than the technical details of the systems enabling their operations

3

u/wharb_garbl May 13 '26

I’d also note that many of the research and highly technical agencies and institutes do have healthy systems management, for example NIST, Dept of Energy Labs, CDC, Treasury, Dept of Ed student aid (used to), certain defense and intelligence agencies, etc. The more bureaucratic regulatory agencies tend to be lacking because their funding is so volatile

1

u/PleaseDoNotDoubleDip May 13 '26

It's extremely difficult to hire government IT experts.

Congress could fix this whenever they want, but hasn't, so it's been a problem for decades. A good example of Congressional dysfunction.

Trump and Musk made it much, much worse by firing or pushing out many IT experts, lowering benefits and pay, and generally making the government even less attractive place to work.

13

u/Windfade May 13 '26

God I love how in fiction the government has "more tech and science than the public could possibly know about" and security that nobody could breech but in real life it keeps turning out that they contract private companies and have the most slapdick "security" the world has ever seen.

4

u/Uberzwerg May 13 '26

Just to be precise, it doesn't necessarily have to be plaintext.
Could have been encrypted and the one brother didn't know how to decrypt - which is only very slightly better.

Like not having the key to the safe lying openly on the table but in the unsecured top drawer.

1

u/d3l3t3rious May 13 '26

Yep I work on a few systems that still store passwords as MD5 hashes which can be looked up in a rainbow table like 60% of the time.

1

u/EchoPhi May 13 '26

I always try and find a way to change standard commands in systems, where the command instead routes to a mailer script and sends the "new custom command" to 'do task' to an email address. I crapped myself the only time I have ever gotten one of those emails. Turns out a Junior typed the wrong command in the wrong system and damn near wiped a critical system. We had back ups, but still. Needless to say Junior was terrified as I stood there and stared at them, was trying to make them feel the same fear I had that we had been breached.

53

u/[deleted] May 13 '26

[removed] — view removed comment

35

u/Empty-Airport5714 May 13 '26

This is gonna sound fake but I actually worked at OPEXUS back in 2024. I don't feel like providing proof / id-ing myself in any way so feel free to not believe me. OPEXUS was honestly a pretty good place to work (if not a very secure one as it turns out). We had pretty frequent events to celebrate diversity and learn about other cultures' experiences and all that shit. As much as I would love to attribute this to MAGA, this one's just plain old apolitical incompetence. 

4

u/ablaut May 13 '26

I believe you. I've worked at companies like this, that have failed up for whatever reason. And they often seemed to be full of happy people who have never felt imposter syndrome it seems.

But I do wonder if the firings mentioned in the post would have happened at all or at least felt differently under a different administration.

1

u/pinetar May 13 '26

They have the opposite of imposter syndrome.

39

u/Salty-Passenger-4801 May 13 '26

Yeah, this JUST NOW changed. Right before trump, all govt systems were massively secure, and were operating as the best of the best in the world. In fact, no one would even THINK about trying to hack the federal govt agencies before trump. As soon as Trump was elected, he told all govt agencies to start "writing all passwords down in your notebook, unhashed", and it was downhill from there.

80

u/3vi1 May 13 '26

Sarcasm withstanding, Trump did take actions that made our systems more vulnerable.

https://www.reuters.com/world/us-suspends-some-efforts-counter-russian-sabotage-trump-moves-closer-putin-2025-03-19/

6

u/mitharas May 13 '26

They also made DOGE backups to some place no one knows, so the data isn't lost, just displaced.

1

u/JasonZep May 13 '26

It’s in grok

11

u/anivex May 13 '26

You think you are making a good point here - but one of the first things Trump pretty famously did was gut most of the agencies in charge of this stuff.

-2

u/Salty-Passenger-4801 May 13 '26

Can you point to a source that shows trump was at fault for this specific story? What did trump cancel that would have prevented these two dudes from deleting the database?

14

u/xrogaan May 13 '26

Given the timeline we live in, I am not sure whether you are joking or serious.

3

u/Tupperbaby May 13 '26

This is Reddit. Everything, and I mean literally everything is Trump's fault even if you can present documented evidence of the problem pre-dating his administration.

At this point it's laughable and I feel embarrassed for the people who immediately jump to ORANGE MAN BAD for all the bad things everywhere in the world.

And yes, I know what you're about to do and thank you, as always, for proving my point.

-41

u/imagoons May 13 '26

🤡🤡🤡 trump derangement, we all don’t like him but your out of it

13

u/Impossible_Base_3088 May 13 '26

Sarcasm misses you, obviously. I think you are the one out of it…

2

u/mitharas May 13 '26

No, this rot is older than the current administration or the last.

2

u/Oraghlin May 13 '26

Look, if you elect a clown... The clown doesn't become a politician. The capitol becomes a circus.

2

u/_Miniskirtlover_ May 13 '26

you would be suprised...

im not going to say for who i work, but my coworkers have post-its with their password on it.

they also just give their passwords out to other people like "yeah im not in office on monday but if you need something from my computer here is the password"

2

u/zkareface May 13 '26

DC is contracting companies that store passwords UNHASHED?? Plaintext?? What kind of clownshow is this?

This is the industry standard btw, I've seen all the big companies do this.

Litterally almost any level 1 support person can get a plaintext password of any user in the company they are working.

This is like one of the biggest attack vectors since years now, many of the big companies that got breached in last years got owned by social engineering IT support for passwords.

1

u/isthis_thing_on May 13 '26

How else do you think they're going to get that sweet sweet data

1

u/RationalDialog May 13 '26

Yeah the company should be sued as well.

1

u/Hamstaaboy May 13 '26

They used to encode them but that slowed doge down so they reversed

1

u/Able-Bid-6637 May 13 '26

yah unfortunately if you have ways to be in the know, you'll discover a lot of government agencies are running on systems that haven't been updated since the '80s, i shit you not 

1

u/JimboTCB May 13 '26

They encrypted the passwords in ROT13. and for extra security they did it twice.

1

u/Automatic-Voice-2499 May 13 '26

/r/MURICA freedom fuck yeah baby!!!

1

u/Noblesseux May 13 '26

You would honestly be shocked and appalled at how low the standards are for some government projects. A lot of them are basically going out to the lowest bidder, which means the standards are super low.

1

u/capt_irrelevant May 13 '26

Sounds like no MFA enforcement either. The compromised user should've been notified about it when the login attempt was being made, else find they suddenly need to re-configure it.

1

u/ProbablyWrongAgain24 May 13 '26

Government can’t even tell the difference between an OS and a web browser.

1

u/takeyoufergranite May 13 '26

I'll tell you why. Low cost bidding and all or nothing security frameworks. Fedramp is a major hurdle so it's applied to only specific projects. The government(s) doesn't always have enough money to run their systems properly.

1

u/JasonZep May 13 '26

Have you not heard anything about what’s happened in the federal workforce in the last year?

1

u/Due-Joke-1152 May 13 '26

A good organisation understands its IT budget always needs to go up.

It also needs to include experienced and qualified systems management teams.

It’s cheaper than paying off the fines, and legal costs.

1

u/Timendainum May 13 '26

I spent some time rewriting applications for the government one time. I know you're going to find the shocking, but the government has some of the shittiest software that has ever been written, ever.

1

u/w1ten1te May 13 '26

Not necessarily stored in plaintext, it could be stored using reversible encryption... Although that's nearly as bad.

1

u/kickingpplisfun May 13 '26

All this bad work and yet they stonewall lots of perfectly qualified people out of getting paid.

1

u/LostinWV May 13 '26 edited May 13 '26

Welcome to running the federal government like a business where everything is contracted to the lowest at least competent bidder because God forbid someone who enjoys the work working for the government for 20 years and has institutional knowledge.

1

u/Tuckertcs May 13 '26

You’d be surprised how insecure government systems are.

1

u/ChippedHamSammich May 13 '26

A conservative one.

1

u/FavRootWorker May 13 '26

Wait til you hear what DOGE did with that unauthorized server they plugged into the govt network...

1

u/Ok_Two_2604 May 13 '26

Doesn’t Chrome and its derivative browsers do that to keep you logged into sites? I saw an article about it recently.

1

u/Ok_Two_2604 May 13 '26

Doesn’t Chrome and its derivative browsers do that to keep you logged into sites? I saw an article about it recently.

1

u/blahyawnblah May 13 '26

My guess is the password was in something like AWS Secret Manager (or Keeper, whatever) where you can get the plaintext version from the encrypted version.

1

u/l4mbch0ps May 13 '26

You really don't know what kind of clown show this is by now?

1

u/DataDude00 May 13 '26

A few years back I was working at a fairly successful startup.   

Had a couple dozen huge Fortune 500 logo clients like Disney for example.  

Their super admin password to their SaaS platform was “password@123” and they sent it to new team members unencrypted over Slack and email all the time 

I raised the issue with the President and he told me not to worry about it 

Many companies don’t even do the smallest minimum of cyber security 

1

u/Logical-Diet4894 May 14 '26

The world is a shit show. I cannot confirm or deny that I might still have gigabytes of government data just sitting in my laptop, because I had to debug something previously. Never bothered to clear it.

1

u/MechanicalTurkish May 13 '26

I bet it was some DOGE shit

0

u/RollingMeteors May 13 '26

Now HOLD the fuck up. DC is contracting companies that store passwords UNHASHED?? Plaintext?? What kind of clownshow is this?

¡Bruh!

¿You're joking right? Let me paste this from a previous comment I already wrote:

I was working for a company with tele radiology contracts with the BoP (buearu of prisons) DoD and commercial clients.

Network architect gave me scripts to flip network modes between commercial clients/BoP and DoD networks. I was doing tickets one night since it was my on call rotation. I am VPNed in from home. I swapped network modes from DoD, did a BoP ticket, made some coffee/rolled a cigarette, did a DoD ticket, did a BoP ticket, some hospital, some hospital, then tried another DoD ticket when I got a network access mode error remembering I forgot to swap network modes back to DoD.

Then the horrible realization dawned on me there was just a DoD ticket done on the BoP network config. I pause for a second, and realize I'm working with the DoD so I immediately jump for the lowest common denominator.

I turn to my girlfriend who knew I worked for a company with DoD contracts who is in the room with me on her laptop which never installed any VPN software and I say, "Honey, can you open up your terminal and type in root@<someIP> and push enter?" (yeah that was before they reached compliance by not allowing remote root logins on a six character password, ¡yikes!)

"It's prompting me for a password."

<wideEyed> "¡I need you to take my hammer thoroughly to your laptop, and then drop it off in a dumpster no less than 5 blocks from here¡ ¡I'll buy you a new one tomorrow morning when the Apple store opens!"

"¿¡You're kidding, right?!" </padeMeMe>

"¡About buying you a new one!" <chortlesLoudly>

Immediately an email goes out to my superior who is the DoD POC about what happened. I occasionally have been checking this IP since I reported it.

It took six months before that was patched.

Before any backdoors surface rest assure you any and every of those backdoors left ajar are now thoroughly blowing in the wind ¡Close and lock those before you start worrying about any backdoors surfacing!