[flagged]

Shooting people in the head because they're not wearing a helmet is still a crime.

What's even funnier is getting upset about people not wearing helmets the second you hear about an accident, with no idea whether people did or did not wear helmets. All the article says is that "the hacker entered using valid credentials." There's no information about how they got the credentials.

Victim blaming is a form of self soothing. If you can get yourself to believe they deserved it, then you avoid feeling that the world is dangerous and you might get hurt too.

There's victim-blaming, and there's gross incompetence.

My own problem with the top-level comment wasn't that it claimed fault on the part of the victims, it's that it didn't substantiate why that claim of fault was applicable in this case.

Multiple use of weak passwords in a critical system isn't acceptable in 2026 (nor has it been for many decades), and yet there's credible evidence (as my own follow-ups in this subthread and my own top-level comments should indicate) that the victims here did contribute significantly to their own harm. For that they should be found accountable. Hosting inherently insecure data systems is gross negligence, quite arguably criminal.

You can downvote all you want, but there were actual admin accounts with the password P@ssw0rd. So in your view incompetence should just be ignored because blaming people for lack of common sense will hurt their feelings?

In this specific case? Documented?

If so, point to references. Otherwise your original comment reads as unsubstantive. Tropes and cliches may have value because they're often true, but if true, in this case, then share that fact and not the trope alone.

https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...

and click on the links in the article - they are screenshots from inside the system.

Like this one for example: https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...

To answer your question: yes, in this specific case, documented.

Sincerely, thank you.

Your initial comment would have been far more substantial, and probably much better received, with these additions.

But you still get fined if you don't wear a helmet

In an ideal world, even before you crash your motorcycle and hit your head somewhere, forcing you to start wearing it

I'll never forget this one video. A cyclist riding with a helmet on was doing everything proper -- helmeted, obeying traffic laws, riding in the proper part of the road...

Then a city bus passes them far too close. The passenger side mirror of the bus catches the rider's helmet and speeds off...carrying the cyclist off of their bike and dangling by their helmet at speed...

Freak accidents occur everywhere. Helmets save a lot more lives then causee deaths overall.

Yep, same with seatbelts... a lot of broken ribs, etc. and people complaining.

If you crashed so hard, the belt broke your ribs, without the seatbelt, you'd be dead right now, head first through the windshield. I mean sure, you wouldn't be complaining about broken ribs, but yeah...

I will never forget your description of the video :(

Do you know that this system was making fundamental security faux pas or are you assuming the reductive argument where determined enough hackers couldn’t break any system with built and maintained by diligent engineers?

Romanian here. There really were admin accounts with the password Passw0rd, created so that some incompetent political apointees could browse the data.

Gee, I didn't know Moscul is helping the Romanian government too! :-)

I'm a quarter Romanian on my step-mother's side, and I too can confirm that the password was Passw0rd.

> Do you know that this system was making fundamental security faux pas or are you assuming the reductive argument where determined enough hackers couldn’t break any system with built and maintained by diligent engineers?

You should take a closer look at the screenshots posted by the hacker: entire systems and network devices with the password P@ssw0rd for the admin user. Now you tell me.

Your comment could have been shortened to:

Take a closer look at the screenshots posted by the hacker: entire systems and network devices with the password P@ssw0rd for the admin user.

Linking those would be bonus.

<https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...>

If you're using passwords as an authentication methods then you've already lost.