Hacker wipes Romania's land registry database

615 points - yesterday at 1:28 PM

Source

Comments

skinfaxi yesterday at 1:59 PM
> Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.

So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.

cbg0 yesterday at 2:29 PM
An update from the land registry (the truthfulness of this remains to be seen depending on how fast this comes back online):

ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.

After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.

ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.

According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.

The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.

The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.

alexpotato yesterday at 2:28 PM
Romanian friends have told me that this is really due to corruption.

Specifically:

- government gives IT/data contracts to cronies

- cronies don't actually do any real security work to protect the data

- things like this happen

khurs yesterday at 3:25 PM

    Security firm KELA... has doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria.

If I was an evil hacker, I would only hack countries my country hated or did not have extradition agreements with. Like the Russian hackers do.

Algeria has a extradition treaty with Romania:

https://periodicos.processus.com.br/index.php/egjf/article/v...

rzerowan yesterday at 10:02 PM
Tangentially reminds me of what happened to the South Korean gov data center [1] where a no-backup ~900TB data center got erased due to a battery fire.

Withno external backups piecing together all the lost functions must havebeen hair raising, and more forensic archeolgy than data recovery.

Last i heard i think they had restored a quarter of the lost services/data.

[1] https://www.intermediagroup.org/south-korea-data-loss/

puritanicdev yesterday at 5:07 PM
Well, the land registry database in Serbia hasn't been working for two months now; the government hasn't issued any announcement so far, except for generic system-issue information we get from LRD support. Weird, hopefully we weren't hit too
osinix yesterday at 5:10 PM
The backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.
Squarex yesterday at 1:57 PM
The same thing happened to Slovakia not that long ago.
dredmorbius yesterday at 7:19 PM
Poor password practice and policy, and likely a lack of 2FA / physical token security, seem to have contributed to this breach.

Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:

<https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...>

<https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...>

Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>.

NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.

ajb yesterday at 3:50 PM
The UK used to have a distributed system - everyone had to have a solicitor store "deeds" of their property, which were a sort of paper blockchain of all the transactions the land had been in since - I don't know, since records began I guess. Since we got a centralised land registry cheaper solicitors have binned these, but some properties still have them as a historical record.
tracker1 yesterday at 5:36 PM
Offline and pull based backups FTW... This is why I advocate for a pull or at least push/pull model for backups... where the remote system pulls backups out of your production environment, or otherwise from a drop point. Because a corrupt production system that controls backups can corrupt backups.

If your production system at most runs a backup to a drop site, then your backup facilities pull down versioned backups from there, you can better ensure older backup files are intact. More so by not allowing the two to see each other at all and not using backup accounts from a system that can access production resources.

ggm yesterday at 9:52 PM
Under the Australian Torrens title system, paper is no longer authoritative and if you bring a deceased estate title document to the registry they keep it after updating the titles registry database, unless you ask to get it back and it's stamped to mark it superseded. I know because I've done this journey.

3 2 1 people.

tiberius_p yesterday at 6:43 PM
The majority of people have paper documents from the land registry. Digitalization of the land registry is a fairly recent development in Romania so people almost always requests papers when they register their land. In the event that all the digital data or large parts if were lost it would be possible to reconstruct it from the papers and interpolate the missing parts if any.
lrvick yesterday at 8:05 PM
Centralized tech is an evolutionary dead end and all who attempt it will continue to learn the same lessons.
javawizard yesterday at 2:57 PM
> HuggingFace got hacked by an AI. What stuck out to me was the guardrail asymmetry. The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models.

This, to me, is the more interesting bit of the article.

I don't really know what a good solution looks like, but yeah, that's annoying.

mdavid626 yesterday at 3:29 PM
Why not just change ownership then? I'd bet some people would be interested to pay some money for that...
luciana1u yesterday at 4:38 PM
we spent centuries building a system to track who owns what land and then put the whole thing in one database that can be deleted with a single compromised password
21asdffdsa12 yesterday at 2:35 PM
Imagine if the hacker was more clever and started writing plausible nonsense into the database, corrupting the backups.
deleted yesterday at 1:59 PM
nailz1911 yesterday at 3:00 PM
arte.tv released a documentary about measuring and registering land just a month ago @ https://www.youtube.com/watch?v=fl7AfiJs5Gk (Romania: The Unmeasured Land | ARTE.tv Documentary)
UltraSane yesterday at 3:05 PM
Enterprise storage arrays have immutable snapshot functionality that makes ransomware easy to recover from.
RandomLensman yesterday at 2:25 PM
What's wrong with an old fashioned paper registry then?
lorreyfum yesterday at 9:55 PM
Who was there first?
danieldrehmer yesterday at 6:58 PM
Dibs on Vlad's castle
iamgopal yesterday at 3:15 PM
would blockchain could have prevented it ?
deleted yesterday at 2:21 PM
rimworld yesterday at 2:58 PM
aka tokenize everything
riazrizvi yesterday at 5:07 PM
Many many times, entire armies have been sent in to adjust another country's land registry.
DesiLurker yesterday at 7:48 PM
I know people flip out when they hear the word crypto but this is exactly why you need blockchain. immutable land registry thats public(anonymized).
johnnyApplePRNG yesterday at 7:38 PM
Incompetent bureaucrats strike again.

News at 11.

charcircuit yesterday at 4:48 PM
Why is deleting the whole database a valid operation? The system should make that impossible.
arisAlexis yesterday at 2:18 PM
We will see a lot of those with open source Mythos equivalent models.
sebow yesterday at 4:23 PM
[Fairly off-topic and political]

There's a growing (retarded) perspective, not only here in Romania but in most of the EU, that we must digitalize at all costs; this itself is obviously not a problem, but it usually comes with the removal of the "traditional" options too. The same goes for payments (removal of cash) and basically every aspect of the administration/society where this could be applied. The most recent concrete example for Romania is the mandatory digital signature by ANAF (IRS equivalent) for all companies.

Unlike other regions of the West: NA/WE/rest of the West (SK, JP, etc.), in EE, people (*younger generations, explained below) don't often think about the aspects of confidentiality that much, or if they do, they usually apply it incorrectly (either IRL [filming in public] or online ["I've accepted a draconian TOS that gives the company rights to all of my data, but I haven't actually read any of it, and now I'm invoking my "GDPR rights" against said company."]).

It does not take a genius or a historian to observe that while the older generations do not have this "problem" (they're very skeptical of the gov. [at least in certain aspects], in an almost american fashion — explained by the fact that they've experienced communism), younger generations position themselves in the extreme opposite; they despise the older generations ("boomers") for being luddites and somehow blame them for the gap in civilizational progress between WE and EE. There is a legitimate point here, of course, but it should be noted that the argument is almost always presented in an emotional, overwhelmingly irrational fashion, and almost never includes comparisons between the centralization done by the state in the past [communists] and the new one attempted by current govs [but digitalized]. (This delves into a broader socio-cultural divide between the generations that includes other aspects like religion, traditions, etc.)

The biggest portion of the so-called "IT people" who call for this "digitalization wave" are midwits, "inverse luddites" (they don't care about the implications), and, in smaller numbers, grifters and second-order beneficiaries (on the "digitalization" gov. projects). Obviously, it should be mentioned that, despite progress, nepotism and corruption are still present, and there are cases where gov. contracts are not given to the best candidate.

As a person who's both working in the IT sector and not a boomer (despite the impression of my comment), "we" should be careful about enabling totalitarians in our endeavors."Hackers" is just one reason out of a multitude of other reasons for not abandoning the sacred paper (see the ES+PT incident one year ago).

ExoticPearTree yesterday at 1:47 PM
[flagged]
DigitResort yesterday at 3:54 PM
[flagged]
spwa4 yesterday at 3:16 PM
Amateurs. Everybody knows you should never wipe databases. You should install a cronjob that makes a random, unrecoverable change on a regular (but random) basis.
m0llusk yesterday at 5:25 PM
Seems like property ownership histories could be one of the few good applications of blockchain technology.
deleted yesterday at 2:34 PM
hughw yesterday at 2:05 PM
Was hoping it was a political act in favor of land reform or against owning property.
c7b yesterday at 2:27 PM
Finally, AI is giving us some real-world blockchain use cases (assuming the attack was helped by AI). Only half joking, BFT is petty much the most adversary-proof security guarantee we can get in a distributed system.