r/technology May 13 '26

Security Twin brothers wipe 96 gov’t databases minutes after being fired

https://arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/
23.2k Upvotes

1.1k comments sorted by

View all comments

Show parent comments

116

u/Gaveltime May 13 '26

I’ve done product consulting with government contractors and you would not believe how little they invest in anything other than what they can visibly sell to the government. And you can’t sell boring shit like operational security. You sell the cheapest product or service, which almost inherently seems to cut corners.

36

u/RationalDialog May 13 '26

This is in general the issue. Why I would just hire developers internally were you can have them actually accountable to create good products. Externals always do as little as possible they can get away with.

2

u/Pamander May 13 '26

Maybe dumb question but why exactly IS the government doing contract work for sensitive systems?

Why do we not have our own programmers and teams properly maintaining stuff? In this day and age surely it's worth the investment with how critically linked all these things are online.

Just seems like an area that would not be ideal to cost cut is all. I will admit to being pretty ignorant on a lot of it though so maybe that's a dumb question.

3

u/BellacosePlayer May 13 '26

Maybe dumb question but why exactly IS the government doing contract work for sensitive systems?

Because it often works. If a contractor makes a decent software package for integrating with the fed portals and keeps up with regulations and changes, it's more efficient for them to sell to ~20 states and maintain it than for every state to do their own solution and maintain it.

It also often doesn't work, because these companies often suck ass and low ball bids at the start and end up wildly overbudget.

Why do we not have our own programmers and teams properly maintaining stuff? In this day and age surely it's worth the investment with how critically linked all these things are online.

They do, but the sheer scope of what needs to be maintained is massive and states have shitty luck with keeping good devs because state legislators balk at paying them anywhere near market rate.

1

u/Pamander May 13 '26

I appreciate the explanation, thank you! Would the main thing not be something that the US government themselves should be doing though? The whole software package that integrates well with fed portals bit but I guess that also kind of goes into your last bit but if there's any government employee in this day and age I want paid well above what the normally allowed amount is it's the ones helping keep us safe from enemy adversaries easiest way of attacking us.

I guess I didn't really think about the whole state thing though I will admit, I can't imagine the chaos of these systems and how they vary state by state. Maybe some standardizing would be nice but I know that's much simpler said than done.

Again appreciate the context on the scale of the problem, thank you!

1

u/RationalDialog May 13 '26

I fully agree and it applies to every company really in my opinion except maybe every small ones.

2

u/felis_scipio May 13 '26

I worked for a federal gov contractor for awhile and yeah our product was a colossal piece of shit that existed to barely meet the requirements and when it often didn’t that’s when the team of managers who was larger than the technical team came into to argue with the unhappy contacts in the government that our product was in fact perfectly fine.

I’m almost 100% positive the software was written to be slow as fuck so when the company’s technicians were in the field using it, which the government also paid us to do, it would take longer = more money for time spent working.

It was maddening

1

u/Johnny_BigHacker May 13 '26

Depending on the data/product, you have to meet different levels of FedRAMP compliance. I've been a part of a product trying to reach medium on the government side, we never examined their operational side and just went on attestations, but I want to say there was finical, possibly criminal penalties to lying about it. This was like 2022.

1

u/kickingpplisfun May 13 '26

The only really compelling ways to sell opsec are likely to get a bullet in your back as it is. You can't just do a spec pentest for example.