5 ms·
Absolutely. You know, like "Confidential Police Informants". And its hella hard to hack paper in a locked filing cabinet, in a locked building, filled with pol
by duckfang 5y ago
Absolutely. You know, like "Confidential Police Informants".
And its hella hard to hack paper in a locked filing cabinet, in a locked building, filled with police.
- rajin444 5y agoIs it harder, or just different? I'm not sure how to objectively compare the two.
- duckfang 5y agoI'd confidently say it's harder. In person documents: requires being at a single location in the world single copy in secured storage in a secured building filled with people who can shoot you legally Online documents: Can be done from anywhere in the world infinite copies can be made easily 1 hack can un-secure the data threatening to shoot a computer doesn't have the same impact Its really a computer hacker versus traditional spycraft. Spycraft isn't impossible, but does require assistance and tech from nation-states, and is prone to a set of really bad negative eventualities if caught.
- kackerd 5y agoRight, but that's not the whole story. Some documents can be permanently offline and still do their job. The list of police informants might be an example. The officer controlling the information writes it down, but he also remembers it. No one else looks at it except, in rare situations like a police corruption investigation, that officer's commander, or an internal investigation unit. Other documents, will need a whole process of retrieving information, copying it, adding info, sending it, checking it, sharing it with other people. Police officers' own personnel records might be an example. If you only store these on paper, informal access procedures might be developed. For example, the civilian secretary is used to certain people requesting copies of 6 or 7 files at a time, so they don't always keep track of what was asked for. Unofficial copies get made and kept in someone's desk drawer so they don't have to spend a morning going over to the main HQ. And so on. Now you have the worst of both worlds - lax security, but also no hope of the traceability and fine-grained access control of an electronic system.
- mashpoe 5y agoI feel like the added complexity of digital storage just means there are more ways to attack and there's more that can go wrong in general. Physical documents can only exist in one place at any given time and are probably much easier to protect.
- FiveMinuteName 5y agoJeffrey Epstein was killed in a maximum security prison while under extreme surveillance.
- TheGigaChad 5y agoAre you an idiot?
- clarkmoody 5y agoCybercrime gangs are more interested in hitting another target that trying to get the most out of any particular one. If some data is offline, the gang can't know that exists. This assumes that they are simply scanning for vulnerable networks and seeing what they can find. A threat actor intent on extracting the informant list of the DC police will have a completely different approach to the hack, probably involving advanced surveillance, infiltration, bribery, etc.
- vageli 5y agoHow many people do you think have attempted to break into your home by trying to pick your door lock? If you set up an SSH instance on the public internet, how many times do you think your login will be tried?
- dylan604 5y agoMy login specifically? Probably a lot less than "admin" "root" or similar common things script kiddies run. But if it is on port 22, the dictionary will probably be attempted.
- vageli 5y agoThis seems tangential unless you have per-user permissions on your front door lock (which people may if they use NFC, etc) but even then, likely have a regular physical key as backup, which for all intents and purposes would be akin to the root account.
- EricE 5y agoBingo. Which is why the second factor in 2 factor authentication is "something you have". It's also why SMS text messages do not meet the criteria for 2 factor authentication - it's trivial to social engineer phone companies into moving a phone number to a new phone - presumably one you would not have. Authentication apps are a PITA to move to new devices because having a way to move your keys around without some reliance on meatspace defeats the whole goal of "something you have".
- selfhoster11 5y ago> it's trivial to social engineer phone companies into moving a phone number to a new phone Obligatory "if you're in the US, then yes - elsewhere, it depends". In the UK, obtaining a PAC code is a bit more complicated/non-trivial for the attacker. I'd consider it fairly safe to use SMS 2FA over here.
- asdff 5y agoOutside of movies, how often do you hear about a police evidence building being raided and key evidence going missing as a result? I don't think it's ever happened in the U.S. at least. Meanwhile, the largest companies there are get hacked all the time with a new article each week seemingly.
- selfhoster11 5y agoI'm pretty sure it's harder. We've known how to do physical security for a very long time, and humans are heck of a lot smarter at recognising strangers/intruders in a secure location where only familiar faces are permitted.
- theatomheart 5y agoAye all the locked filing cabinets in WTC7 have proven to be 100% unhackable to this day! <3