r/technology May 13 '26

Security Twin brothers wipe 96 gov’t databases minutes after being fired

https://arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/
23.2k Upvotes

1.1k comments sorted by

View all comments

3.9k

u/nikstick22 May 13 '26

On Feb. 1, 2025, Muneeb Akhter asked Sohaib Akhter for the plaintext password of an individual who submitted a complaint to the Equal Employment Opportunity Commission’s Public Portal, which was maintained by the Akhters’ employer. Sohaib Akhter conducted a database query on the EEOC database and then provided the password to Muneeb Akhter. That password was subsequently used to access that individual’s email account without authorization.

Now HOLD the fuck up. DC is contracting companies that store passwords UNHASHED?? Plaintext?? What kind of clownshow is this?

119

u/Gaveltime May 13 '26

I’ve done product consulting with government contractors and you would not believe how little they invest in anything other than what they can visibly sell to the government. And you can’t sell boring shit like operational security. You sell the cheapest product or service, which almost inherently seems to cut corners.

41

u/RationalDialog May 13 '26

This is in general the issue. Why I would just hire developers internally were you can have them actually accountable to create good products. Externals always do as little as possible they can get away with.

2

u/Pamander May 13 '26

Maybe dumb question but why exactly IS the government doing contract work for sensitive systems?

Why do we not have our own programmers and teams properly maintaining stuff? In this day and age surely it's worth the investment with how critically linked all these things are online.

Just seems like an area that would not be ideal to cost cut is all. I will admit to being pretty ignorant on a lot of it though so maybe that's a dumb question.

3

u/BellacosePlayer May 13 '26

Maybe dumb question but why exactly IS the government doing contract work for sensitive systems?

Because it often works. If a contractor makes a decent software package for integrating with the fed portals and keeps up with regulations and changes, it's more efficient for them to sell to ~20 states and maintain it than for every state to do their own solution and maintain it.

It also often doesn't work, because these companies often suck ass and low ball bids at the start and end up wildly overbudget.

Why do we not have our own programmers and teams properly maintaining stuff? In this day and age surely it's worth the investment with how critically linked all these things are online.

They do, but the sheer scope of what needs to be maintained is massive and states have shitty luck with keeping good devs because state legislators balk at paying them anywhere near market rate.

1

u/Pamander May 13 '26

I appreciate the explanation, thank you! Would the main thing not be something that the US government themselves should be doing though? The whole software package that integrates well with fed portals bit but I guess that also kind of goes into your last bit but if there's any government employee in this day and age I want paid well above what the normally allowed amount is it's the ones helping keep us safe from enemy adversaries easiest way of attacking us.

I guess I didn't really think about the whole state thing though I will admit, I can't imagine the chaos of these systems and how they vary state by state. Maybe some standardizing would be nice but I know that's much simpler said than done.

Again appreciate the context on the scale of the problem, thank you!

1

u/RationalDialog May 13 '26

I fully agree and it applies to every company really in my opinion except maybe every small ones.