Hacker Newsnew | past | comments | ask | show | jobs | submit | msbhvn's commentslogin

Please do it, I'm very biased but I think there would be lots of interest in seeing all that explained in one place in a coherant fashion (you will likely sharpen your own understanding in the process and have the perfect resource for when you next need to revisit these topics).


Woah, read the timeline at the top of this. The fire happened the very day the government ordered onsite inspection was supposed to start due to Chinese/NK hacking.


Phrack's timeline may read like it, but it wasn't an onsite inspection due to hacking, but a scheduled maintenance to replace the overdue UPS, hence battery-touching involved. Even the image they linked just says "scheduled maintenance."


So right after the investigation was announced, they suddenly scheduled a UPS battery replacement which happened to start a fire big enough to destroy the entire data centre and all data or evidence?

Yeah, that's way less suspicious, thanks for clearing that up.


My mind initially went to a government cover-up, but then:

> 27th of September 2025, The fire is believed to have been caused while replacing Lithium-ion batteries. The batteries were manufactured by LG, the parent company of LG Uplus (the one that got hacked by the APT).

Could the battery firmware have been sabotaged by the hacker to start the fire?


It could have.

But

replacing a UPS is usually done to right time pressures. the problem is, you can rarely de-energise UPS batteries before replacing them, you just need to be really careful when you do it.

Depending on the UPS, Bus bars can be a mother fucker to get on, and of they touch energised they tend to weld together.

With lead acid, its pretty bad (think molten metal and lots of acidic, toxic and explosive gas, with lithium, its just fire. lots of fire that is really really hard to put out.


Don't you have to put UPS's in bypass mode precisely for this reason while doing maintenance on them ?


Yeah, but the problem is that the batteries are still full of juice.

Obviously for rack based UPSs you'd "just" take out the UPS, or battery drawer, and replace somewhere more safe, or better yet, swap out the entire thing.

For more centralised UPSs that gets more difficult. The shitty old large UPSs were a bunch of cells bolted to a bus bar, and then onto the switchgear/concentraitor.

for Lithium, I would hope its proper electrical connectors, but you can never really tell.


this was a plot in a Mr. Robot episode, heh. Life imitating art?


was there a battery hacking episode? I can't remember the show anymore, might be due in for a rewatch it seems.


They hacked the firmware of the UPSs inside e-corp to destroy all paper records. The steel mountain hack was messing with the climate controls using a raspi to destroy tape archives


iirc that’s how they destroyed “steel mountain”.


That's exactly where my mind went!


UPS, check. Any kind of reasonable fire extinguisher, nah.

A Kakao datacenter fire took the de-facto national chat app offline not too many years ago. Imagine operating a service that was nearly ubiquitous in the state of California and not being able to survive one datacenter outage.

After reading the Phrack article, I don't know what to suspect, the typical IT disaster preparedness or the operators turning off the fire suppression main and ordering anyone in the room to evacuate to give a little UPS fire enough time to start going cabinet to cabinet.


If the theory "north korea hacked the UPS batteries to blow" is true, though, then it makes more sense why fire suppression wasn't able to kick in on time.


Supply chain interceptions can happen for batteries and other electronics being used.


https://www.ispreview.co.uk/index.php/2025/09/openreach-give...

Recently in the UK a major communication company had issues with batteries


look at the timeline again. this is the second fire.


technically seems more accurate to say controlled burn


Such coincidences do happen. 20 years ago the plane which was carrying all the top brass of the Russian Black Sea Fleet as well as the Fleet’s accounting documentation for inspection to Moscow burst in flames and fell to the ground while trying to get airborne. Being loaded with fuel it immediately became one large infernal fireball. By some miracle no top brass suffered even minor burn/injury while all the accounting documentation burned completely.


One hell of an act of God that... Believable though, given the consistent transparency and low corruption in the Russian government's administration.


Golf clap, lasting several minutes.

Bravo, old boy.


Quite a few of those top brass years later shot themselves in the head several times before jumping from a window.

Anyway, shoe production has never been better.


So, someone figured out how to do backups


They certainly will after this.


Yeah, this whole thing smells.

Who has the incentive to do this, though? China/North Korea? Or someone in South Korea trying to cover up how bad they messed up? Does adding this additional mess on top mean they looked like they messed up less? (And for that to be true, how horrifically bad does the hack have to be?)


It might be different “they”s. Putting on my tinfoil hat, whoever was going to be in hot water over the hack burns it down and now the blame shifts from them to whoever manages G-drive and don’t have a backup plan.

Not saying I believe this (or even know enough to have an opinion), but it’s always important to not anthropomorphize a large organization. The government isn’t one person (even in totalitarian societies) but an organization that contains large numbers of people who may all have their own motivations.


If there was shady behavior, I doubt it’s about a cyber hack. More likely probably the current administration covering their tracks after their purges.

Alternate hypothesis: cloud storage provided doing the hard sell. Hahaha :)


“It’d be a real shame if something happened to your data center…”


> whoever was going to be in hot water over the hack burns it down and now the blame shifts from them to whoever manages G-drive and don’t have a backup plan.

LG is SK firm and manufacturer of hacked hardware and also the batteries that caught fire. Not sure it’s a solid theory just something I took note of while thinking the same


Interesting but same concept applies to organizations.


The good news is: there are still off-site backups.

The bad news is: they're in North Korea.


"Your Holiness! I have terrible news! Jesus has returned!"

"But that's a blessed event? How could that be terrible?"

"He appeared in Salt Lake City."


"NK hackers" reminds me "my homework was eaten by a dog". It's always NK hackers that steal data/crypto and there is absolutely no possibility to do something with it or restore the data, because you know they transfer the info on a hard disk and they shoot it with an AD! Like that general!

How do we know it's NK? Because there are comments in north-korean language, duh! Why are you asking, are you russian bot or smt??


To paraphrase Bob Metcalf, “I don’t know what will come after Ethernet, but it will be called Ethernet.”


In Peru debit cards don’t have names on them. So you just go to a branch and they take an unused one off the stack and assign and hand it to you. 5 mins, any branch, no appt. Quite convenient. Credit cards do have your name printed on and those you pick up at a branch when they arrive.

I guess the US considers the printed name to be more important for debit cards.


In the US, debit cards and credit cards are processed by the same systems (by the same few handful of companies), so usually the only way you can tell the two apart visually is if the debit card literally says "debit" on it.

Merchants have the option of verifying the cardholder by comparing the name to some photo ID but it's very uncommon. There is a box on the back to sign the card but in my experience, the Post Office is the only entity that has ever checked it.


My impression was that if you sign it, they’re not supposed to ask for photo ID because the card company is bearing the risk (they could instead check the signature against the one on your receipt)


In Kazakhstan, we have debit card “ATMs”. You can have a named debit card printed out for you in a matter of minutes. All you need to do is to have it scan your QR in the bank’s mobile app. It’s quite convenient.


Seems like they provide an autossh+GUI subscription service that maintains reverse port forwards? If you do not have a public ssh host to connect to then this is an option.

Things being how they are and the app being Chinese, I guess I would need more convincing on why I should trust them first.


Segmentation and checksumming are very common, with the segmentation often called TSO (Transmission Segmentation Offload) for send and LRO (Large Receive Offload) for receive. However, usually when referred to as a TCP Offload Engine (ToE) it does mean pretty much the whole protocol, as least a functional subset of it anyway. Windows and FreeBSD support ToE with some NICs. Linux has rejected full ToE in mainline for a number of pretty solid reasons:

https://wiki.linuxfoundation.org/networking/toe


Just to be clear, "TCP Sucks", despite successfully running the majority of the global Internet traffic. "TCP Sucks" so bad we're basically going to copy a lot of it: window based congestion control, SACK, timestamps, ability to add new options, etc. "TCP Sucks" because it is not perfect and has an issue, an issue that requires router / switch upgrades. We're going to fix that by breaking backward compatibility with _tons_ of applications and requiring an OS update on _every_ client and/or application. All this assuming our relatively new and unproven thing is as good as TCP in all other ways and fixes this issue of TCP perfectly.

Hmmm. Me thinks that TCP does not suck so much.


Sounds like "it kind of worked so far, so let's use it forever, with multiple layers of band-aids if necessary". Besides, unles I'm missing something, the two protocols can be used side-by-side, I.e. you can slowly phase one out by the other where necessary.


Did you read the article or just the headline?


I did read it, guess I just got too caught up in the title to brush it off (looks like some others here also wondered about that).

Anyway, uTP looks cool, LEDBAT sounds very interesting and BitTorrent is of course, completely awesome. I just don't think TCP sucks. I'm constantly surprised at how well it works for how simple most of it is and how complicated and intractable the rest is.


The former Sun CEO does not agree: http://www.wired.com/wiredenterprise/2012/04/schwartz/

Oracle on the other hand argued that he (former Sun CEO) was not qualified to answer legal questions about Java.


So Apple gets attacked for not allowing their OS to run on non-Apple hw and Google gets attacked for allowing their OS to run on non-Google hardware? (I realize they're actually being criticized for now having their own device here, but just another perspective). I guess you could just not have your own hardware, since that's working so well for WinMo.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: