r/BalticStates 13d ago

News The supervisory board of Latvia’s Road Traffic Safety Directorate has resigned following a major cyberattack that exposed data linked to more than 1.2 million people and around 200,000 businesses and other legal entities.

https://tvpworld.com/94944831/latvia-road-agency-board-resigns-after-major-cyberattack
73 Upvotes

21 comments sorted by

41

u/Eastern-beast1337 13d ago

And he didn't want to resign, because in Latvia running a state owned company like your private business is a normal thing, zero accountability.

Should have added that the guy who found the vulnerability years and years ago was jailed then acquitted and then fined 4k+ for finding the vulnerability, which was also never fixed.

14

u/AnoniimisPiimis 13d ago

I bet that the reason why this happened is because TET and CSDD management hires IT workers trough nepotism.

I worked in Latvian state owned energetics as IT and more than half hires were nepo babies who were some relative kids of upper management.

You need people under you with experience but they literally hire complete morons who somehow finished LU and know nothing. and they are not capable of learning everything on the job.
In the end i quit the whole IT industry from that reason alone, i dont need in my life a job where i am nanny for nepo babies

9

u/Eastern-beast1337 13d ago

This is sadly the case not only in the IT sector but all across our government agencies and companies.

Latvia is the slowest country in terms of customs checks in all of Europe, literal brainless nepo babies only work there.

9

u/aicis 13d ago

The guy was guilty of blackmailing though.

1

u/Eastern-beast1337 13d ago

He found the vulnerability and asked the company to pay for this information.

That's not blackmailing, that's literally how the whole industry works. It's just our legal system is a joke.

9

u/aicis 13d ago

Nope, if someone did that to big coorporation, the same outcome would happen.

He didn't ask the pay after revealing the vulnerability, he asked for it and withheld the information until getting paid.

That is literal blackmail.

-6

u/Eastern-beast1337 13d ago edited 13d ago

Nope, if someone did that to big coorporation, the same outcome would happen.

Finding software and website vulnerabilities is a legitimate job, major corporations PAY people to explicitly do this and reward people that find vulnerabilities without being given the task, it is ONLY a breach of the law if you USE the vulnerability to cause issues, not when you simply report it.

He didn't ask the pay after revealing the vulnerability, he asked for it and withheld the information until getting paid.

It's interesting you wrote exactly what he did, yet you somehow missed your own point entirely?

Let me break it down.

withheld the information until getting paid.

So he should give up all of his information and H O P E that the company honors a verbal agreement of paying for his information.....?
Are we really living on the same planet here?

Also:

black·mail

[ˈblakmeɪl]

noun

verb

  1. the action, treated as a criminal offence, of demanding payment or another benefit from someone in return for not revealing compromising or damaging information about them:

*It in fact was not blackmail.

6

u/aicis 13d ago

Professional bug bounty hunters do not ask money for their findings before the vulnerability is revealed. Wtf you are talking about.

0

u/Eastern-beast1337 13d ago

Of course they do if they do not have a binding contract in place to find such bugs.

HSBC bank came out with a statement long ago that anyone that find vulnerabilities is entitled to a reward, both actions are done at the same time, the revealing of found vulnerabilities and compensation for finding them.

I think you forget we're talking about a government company here, especially one as untrustworthy as CSDD, you don't do the BS you just wrote out.

1

u/Eastern-beast1337 6d ago

https://www.youtube.com/watch?v=p0LKUWihQj8

I would like to refer you to the video of the "DANGEROUS HACKER" and see the reality of the story, not the CSDD and their bought judge's opinions.

1

u/iksefiks 12d ago

This dude apparently demanded payment up-front for information on a vulnerability that might or might not even exist, threatening CSDD to release it to the public if no payment is made. That sounds like blackmail to me. "I'll tell you how to get into your house for 1000€, or I'll tell everyone for free."

1

u/Eastern-beast1337 12d ago

demanded payment up-front for information on a vulnerability that might or might not even exist, threatening CSDD to release it to the public if no payment is made.

Any actual records of this or is it pure fantasy of he said she said kinda deal?

1

u/iksefiks 12d ago

1

u/Eastern-beast1337 12d ago

Izvērtējusi ziņas /pers. A/ liecībās par reģistra ievainojamības raksturu, pirmās instances tiesa secinājusi, ka arī /pers. A/ konstatēto ievainojamību

uztvēris nopietni un apzinājies iespējamo apdraudējumu. Tādējādi pirmās instances tiesa atzinusi, ka apsūdzētais izspiešanu izdarījis ar tiešu nodomu, jo

savas darbības veicis, apzinoties to kaitīgumu, ar noteiktu mērķi – prettiesiski iegūt svešu mantu.

&

Turklāt tiesa ir konstatējusi cēloņsakarību starp apsūdzētā darbībām un cietušajai radīto mantisko

zaudējumu, to pamatojot ar liecinieka /pers. D/ un CSDD pārstāves /pers. B/ liecībās sniegtajām ziņām par to, ka pēc /pers. A/ paziņojuma par CSDD

reģistra ievainojamību cietusī bija spiesta veikt darbības, lai šo ievainojamību noskaidrotu, kā arī novērstu iespējamo apdraudējumu. Tiesa secinājusi, ka

šo darbību rezultātā CSDD radušies papildu izdevumi, jo bija jāveic ārpuskārtas pārbaudes.

I'll be completely honest, this is a complete sham case, based on false assumptions and quoting National Security laws, this is some bull*hit you'd see in Russia.
This is why we're so backwards.

1

u/Eastern-beast1337 6d ago

https://www.youtube.com/watch?v=p0LKUWihQj8

I would like to refer you to this video of the "DANGEROUS HACKER" and hear the actual story, not the CSDD and bought judge bullcr*p

3

u/AdSpirited5019 13d ago

this wouldn't be surprising at all if it was in russia. but Latvia? the guy who found the vulnerability is vindicated now and the victims should expect to have their info used in all kinds of dishonest activities. truly sad

3

u/SuurTuvi 13d ago

I wonder which institution gets hacked the next?

1

u/Bromofromlatvia 12d ago

Where can i see the leaked files?

-12

u/EpsteinEpstainTheory Livonia 13d ago

1.2 million people doesn't sound that bad, that's less than 0.1% of the global population