upvote
As a Romanian I can tell you that most of the corruption happens through "dedicated contracts", or outright syphoning.

In this case I expect an underpaid employee, and at most an incompetent nephew of someone. They had no reason to have an .authorized_keys file in the webroot of the website, and yet they did.

If you want to know what "dedicated contracts" look like in practice they are overly specific requirements than can only match a single business. The best example that comes to mind was when one county needed to buy busses (or vans) and the maximum length admitted was bellow the most common options, but as luck would have it a nephew of a cousing of someone with decision power (or something like that) just so happened to be the one importing cars that precisely matched the specs.

reply
If it is any consolation, this kind of corruption exists in many countries. I don’t know how to fix this, but corruption always finds creative ways.

Here is one I learned recently - govt started issuing birth certificates online. Hopefully Less corruption, right? Officials made deliberate spelling mistakes in names etc, because you have to go in person for corrections. In person means bribe, which means back to same situation as before (almost)

reply
yeah, i know that this exact thing happens in Switzerland a lot. arbitrary requirements which make sure that only one specific company will be able to deliver.
reply
Same thing is rampant in other Eastern European countries as well. Tips on how to address this for those of us that are publicly minded?
reply
It's no different anywhere. Security isn't valued since it's just an email and a .01% or less income fine.

The amount of times my SSN and correlated info has been leaked and I've been offered a free year or credit monitoring is depressing.

reply
Problem really is that things like SSN or ID numbers should have never been treated as more as just one possible semi-public unique identifier. Never anything to be used in identifying a person for a contract.
reply
This would implicate close to 100% of American firms and most of the adult population?

If they are clearly misusing a system (SSN) never designed nor intended that way. And continue to do so even after being shown the facts.

reply
There is a somewhat valid argument to be made that aggressively trying to hack these insecure government portals could lead to a real reprioritization towards competence.
reply
deleted
reply
I'd say form an IT firm and bid on government contracts and do honest work, but we all know how that goes in reality. Honest workers don't get the contracts. You can still try, though.
reply
Sometimes it can happen that the honest company gets a visit from the dedicated contract crony, with the offer to do the real work for like 50% of the contract value. At least the taxpayers get something usable - if that 50% amounts to something usable.
reply
I'm sure it's obvious to anyone living in a corrupt/oppressive regime, but in case it's not obvious to everyone.

Corruption and oppression are signaling and coordination problems. The illegitimate sovereign is exploiting informational assymmetry: they know your neighbors are just as angry as you, they know it because all the walls have ears.

They need to prevent you and your neighbors all knowing it at the same time. Your best play is to find some signal, something difficult to censure, hard for the goons to pick out in a crowd but legible to your neighbors. If you all knew that the first guy to shove back when the cop shoves you is going to be followed by a swarm of guys? Very easy to find the first guy in that case.

This is why shit like extremely high gas prices scares the shit out of illegitimate sovereigns: they're the ones posting pure data about why everyone should be that angry right now.

reply
Are high prices really that bad for the sovereign? Most of them seem to just blame some scapegoat and it works. Remember how Germany responded to hyperinflation?
reply
Vote and join a party
reply
Look at what the new Hungary PM is doing
reply
Use EU funds to build it then tip the EPPO when they defraud the funds?
reply
Many many many contracts and systems refuse to use EU funds exactly because of this - they become traceable.
reply
Somebody vibed an explainer dashboard with what surfaced online about the incident https://ancpi-atac.mariuscomper.uk/en/
reply
It is not corruption. Or not just corruption.

A close relative, government employee, was in charge of building a new application. They have nobody in that entire organization of several thousands people that know how to write specifications for an IT application, nobody that knows how to design, test and deploy it. This is because some government employees have decent salaries, but in IT the private sector is paying a lot more, so almost anyone remotely competent is going to the private sector. So in this case an organization of non-IT people had to deal with the contract and all the associated problems - there is no need to guess, it did not go well. That kind of project could have been done properly with ~ 10% of the budget in the same timeline.

I have a friend that worked as a developer in such a government IT project. The project cost was ~ 5-10 times what was worth, a chain of sub-contractors did the work, less than ten competent people doing the project, charged by the bid winner for over 100 people and actual staff was around 70 at most, for a short period of time.

Both projects above are in Romania. Lack of competent people in the projects, especially in decision roles, was the main problem.

reply
They said this in the article:

> Sources told Risky Business that the hacker entered using valid credentials

reply
This is the same in the UK too. Governments everywhere are the same. It's just humans motivated by greed and easily corruptible.
reply
"It's corruption and cronies" is a generic cop-out answer that doesn't explain anything.

Like whenever someone gets caught in a compromising situation they say they "were hacked", as if saying that means anything.

reply
Its a bit more nuanced than that. The company responsible for ensuring the cybersecurity of the system told the press that "they secured what the client told them to secure and it was not their job to tell the client what needs to be secured".
reply
And I think it's a label that's used freely on Hacker News against Eastern Europeans
reply
It's always amusing how this is always attributed to the corruption.

It's even more funny on Reddit when you can see the person who is blaming cronies in his Romania but has posts of him doing some blue-collar work in the Midwest.

reply