All posts by Davi Ottenheimer

Liar, Liar, Underbody on Fire: Tesla Sanctioned Twice Before Trial

Tesla told a Florida court it could find no Test Incident Reports from its underbody impact testing. Its own test protocols require a report, photos and video for every run. Well, that doesn’t make any sense, does it? Could Tesla be lying in court, again? Then its own witness, Adam White, testified the reports can be located by clicking hyperlinks in the company’s system.

Circuit Judge Michael A. Robinson called the claim “not credible”, probably because court hates calling people liars, and wrote that it “appears to have been a willful and/or intentional misrepresentation.” Liar, liar, why can’t we just call Tesla the liar it has been and continues to prove itself?

That was the first sanction in Alcala v. Tesla Florida. The second was issued August 19. Trial is set for November 30.

Underbody Underengineering

Nicholas Garcia, 20, drove a 2021 Model 3 through the intersection of Alhambra Circle and Coral Way in Coral Gables with Jazmin Alcala, 19, in the passenger seat. The underbody struck a crest in the road. The battery pack ignited. The car veered onto the median, glanced off one tree and struck a second with its passenger side. Both occupants died in the fire. The date was September 13, 2021.

Garcia had owned the car for about six days. Four days before the crash he had taken it to Tesla service for steering and suspension complaints. Six weeks after the crash, Tesla filed recall 21V-835 with NHTSA, covering 2,791 Model 3 and Model Y vehicles whose front suspension lateral link fasteners could loosen and separate from the subframe.

The NTSB preliminary report recovered five seconds of data from the event recorder. Maximum recorded speed was 90 mph on a 30 mph street, accelerator applied to beat a yellow light, service brake off. Tesla’s defense rests on that data. The family’s case rests on how the underbody and battery pack respond to road contact.

Tesla’s own tests address that question, and Tesla has spent three years fighting to prevent transparency into it.

Willful Disregard for Safety

The family filed in October 2021. The discovery record follows.

September 20, 2023. The court ordered Tesla to produce an engineer responsible for stability control. Tesla produced Daniel Wood, who testified that the engineer “personally responsible for the stability control” would be better placed to answer. Tesla designated no one else. Judge Robinson found this “a direct violation” of the order.

November 6, 2023. The court compelled testing documents for real-world driving situations, including speed bumps and uneven surfaces. Tesla’s counsel told the court everything responsive had already been produced. Over the following year Tesla produced no additional testing documents. The withheld material included the Sine Wave Test, which Judge Robinson found “substantially similar to the crest in the roadway that was involved in the subject incident.”

March 7, 2025. Five days before a scheduled deposition, Tesla produced 8,100 pages of test reports. The documents state on their face that the tests simulate conditions in which the battery pack and underbody make direct contact with the ground, bumps, curbs and other objects, to reproduce severe unintentional customer usage constituting an accident.

June 12, 2025. Tesla’s counsel wrote that Tesla “did not locate any TIRs.” The court found the opposite, that Tesla “was in fact in possession of thousands of pages of TIRs.”

Just call them liars, seriously. Nothing they say can be trusted. It’s like the courts don’t yet have the power to shut the whole thing down? How long did Enron stay in business?

July 2025. Four days before the sanctions hearing, Tesla produced 123,000 pages with metadata and file names stripped. Judge Robinson found this was done intentionally and that the acts “were intended to make the review and use of these materials more difficult, time consuming and expensive for the Plaintiffs.”

Imagine a company that knows it’s killing its own customers, and then tries to pull as much time and money as possible away from anyone who complains.

Source: My presentation at MindTheSec 2021

October 24, 2025. Judge Robinson granted the first motion for sanctions. He found Tesla “acted willfully or with contumacious and deliberate disregard” for two court orders, awarded the plaintiffs fees and costs including expert time spent reviewing the July production, and warned that continued violations could result in Tesla’s pleadings being struck.

So many warnings, so much time.

The Tracker

A separate dispute concerns Tesla’s internal incident tracker. Tesla claims the file was assembled at the direction of counsel and is privileged. The plaintiffs argue the TREAD Act requires Tesla to report similar incidents to federal regulators, which places the tracker outside privilege. A special magistrate ruled that Tesla’s witness must answer who has access to the tracker and what it contains. Judge Robinson affirmed over Tesla’s objections, with the contents themselves protected pending appeal. Tesla has said it will seek review from the Fourth District Court of Appeal.

Fraud: Second Sanction

The family filed a third motion for sanctions in May 2026. The motion and Tesla’s response each exceed 300 pages. Both are redacted in full as confidential. You would think Tesla is building some kind of military secret, like AI-based drones, given how they treat their products as super secret squirrel stuff. It reminds me of the kids in “Teenage Wasteland” who jumped the “no trespass” signs at the Wallkill landfill and exposed a mafia toxic dumping operation in upstate New York, with Ford Motor Company among the dumpers.

Middletown High School student reporting from the Wallkill landfill, early 1990s. Trespassing produced the evidence that officials, the local paper and the dumpers spent years denying. Source: Teenage Wasteland, Netflix, 2026

Retired Circuit Judge Charles M. Greene, sitting as special magistrate, heard the motion August 14 for three and a half hours, most of it closed to the public. Todd Falzone of Kelley Uustal told the court Tesla had violated three orders, paid monetary sanctions and continued to withhold. The production to date covers component testing. Vehicle-level testing under roadway conditions has yet to be produced. Franklin Sato, for the Garcia estate, called Tesla’s conduct “tantamount to fraud.”

Val Leppert of King & Spalding answered for Tesla. Eleven thousand documents produced, 9,000 of them testing records. Engineers made available for deposition. One hundred fifty hours spent building a mapping tool linking documents. Their production failures were “copying errors, misunderstandings and false starts.”

“We have not been perfect. There has not been any intentional withholding.”

The company that builds a car on the claims that it can automate better than humans, that it can define safety as a baseline, flails and falls down on basic document delivery tasks and begs for forgiveness. Yeah, nobody should trust that company with anything related to life or death decisions privately let alone on public roads.

Judge Robinson’s October order found the withholding willful and intentional and described a misrepresentation to the court.

Judge Greene issued his recommendation five days after the hearing. Tesla’s pleadings stand. He recommended an adverse jury instruction at trial, a further award of attorney fees, and compliance with the outstanding discovery. According to the family’s counsel, the instruction tells the jury Tesla knew its own testing had shown failures similar to the one at Coral Way.

That sounds right to me. Tesla has known since 2013 that AI was a wildly unstable theory, a pipe dream, and by 2016 knew Musk was lying about it to the press, even as two fatalities proved the system too dangerous for production. In March 2018 Uber killed a pedestrian in America and suspended all road testing the same day. In April 2018 Tesla killed a pedestrian in Japan, and two months later raised the price of Full Self-Driving from $3,000 to $5,000 while expanding the program. Most Americans haven’t heard about it because Tesla litigated to keep it all in Japanese. The constant rise in crashes and rise in fatalities came after they knew it would.

Tesla’s own SGO reports to NHTSA, 207 crashes in May 2026, the highest month on record, January through June counts of 180, 261, 269, 476 and 826 across five years, a 4.6x increase, or +359%. The last two years each added more crashes than the entire first-year total. Source: Electrek

Going Back to Grimshaw

The Ford Pinto verdict rested on discovery. Ford’s rear-impact crash tests showed the fuel tank rupturing at moderate speeds. Ford produced the tests and a jury saw them. In Grimshaw v. Ford Motor Co., 119 Cal.App.3d 757 (1981), the Court of Appeal upheld punitive damages on the basis that the tests established what management knew.

Tesla’s approach in Alcala differs at the production step. Four years of orders, a production timed to a deposition, a second production timed to a hearing with filenames removed, a letter denying the existence of reports its own witness said were one click away, and a sealed 300-page attempt to call all of that purely accidental. It’s like they don’t believe in the laws of physics or the laws of America, operating above the laws and unaccountable while those who trust them are burned up or silenced.

Teslas notoriously “veer” uncontrollably and crash. Design defects (e.g. Pinto doors) trap occupants and burn them to death as horrified witnesses and emergency responders watch helplessly. Source: VoCoFM, Korea, 2024

Tesla’s litigation position in Florida has been that it could never have known its cars would kill. It’s an incredible claim, given that I was giving keynote presentations in security conferences by 2016 that Tesla is the Titanic of our time, because their AI would kill far more people, let alone all the times I’ve written it since then on this blog.

In the Benavides Autopilot case, plaintiffs alleged withheld data and misdirected police; the jury returned $243 million and Judge Beth Bloom upheld the verdict in February 2026. The Alcala family alleges the same discovery pattern with respect to the battery and underbody.

An adverse inference instruction tells the jury that a party withheld evidence and permits the jury to infer the evidence would have been unfavorable to that party. Let’s see what happens when Tesla goes to trial at the end of November.

Disinformation Pushed by 1Password: Their AI Patching Report is False

August 6, 2026: 1Password launched a research unit called Off-by-1 Labs with a paper reporting that two frontier models cleanly fixed the target vulnerability in 26.0 percent of the patches they generated and introduced new vulnerabilities in 4.5 percent.

Do you believe it?

The blog post put the defective share at 53.9 percent. The Register and Help Net Security carried the figures the same day.

However, on pages 19 and 20 the same paper admits the grading system generating the numbers missed most of the defects it had been built to catch.

Record scratch. How does that happen?

Bad instrument

Off-by-1 generated 6,480 patches with Claude Opus 4.8 and ChatGPT 5.5 against six recently disclosed CVEs, removed 400 where the model had located the real fix, and graded the remaining 6,080. The grading, which produced every headline number, went wrong in three ways.

First, the graders were the models under test. Claude and ChatGPT scored their own patches and each other’s. A study of whether models can verify patches used models to verify patches, so any blind spot in the models became a blind spot in the score.

Second, the graders were wrong one time in three. Section 2.8 reports that the automated grade matched the authors’ own human review 65.9 percent of the time. Every number in the abstract comes from those grades.

Third, the answer key was wrong. Graders were told to treat the maintainers’ upstream fix as correct. For the Linux kernel CVE, “Copy Fail,” the upstream fix was the maintainers’ revert a664bf3d, which carried an off-by-one bug that the maintainers corrected one commit later in 31d00156. The key given to the grader contained the bug and omitted the correction. A model that reproduced the kernel bug matched the key and was scored as a correct fix.

What was recorded

The authors found the grading failures themselves and wrote them down.

Section 4.4: 129 of 400 ChatGPT patches and 119 of 383 Claude patches for Copy Fail reintroduced the kernel off-by-one. The grader caught 14 of the 129 and 10 of the 119. The authors write that the regression is almost entirely absent from the reported new-vulnerability rate. In plain terms, 248 patches shipped a known kernel bug and the headline 4.5 percent counts 24 of them.

Section 4.9: for the Chromium use-after-free, between 38.5 and 41.9 percent of patches that used the correct fix architecture moved the vulnerability into a callback instead of removing it. The grader scored many of them as clean fixes. Those patches are inside the headline 26.0 percent.

So by page 20 the authors knew the new-vulnerability rate was undercounted and the clean-fix rate was overcounted, and they knew by how much on two of six CVEs. Tables 7 through 10 were published unchanged. The abstract carries the 26.0 percent, as does the conclusion. The blog post carries it, keeps the word “complex” in its first paragraph while dropping it from the title and the chart caption, and omits the 65.9 percent and both sections above. The press coverage repeats the blog’s figures and therefore makes the same omissions.

The reader who stops at the abstract gets the number. The reader who reaches page 20 learns that number is wrong. The authors wrote both. Now ask yourself why they led with the first.

What is heard

Propaganda is based on a grain of truth. The question is can readers tell that grain from what is being built on top of it.

The 248 count is that grain. The off-by-one patches were found by comparing each rewritten function against the corrected upstream fix, a structural check that used no grader. Anyone with a checkout of the released dataset can rerun it and get the same number. That makes 248 true, and yet it appears in neither the abstract nor the blog.

Two behavioral findings also hold. Models patch the path shown in the proof of concept and miss the parallel path that reaches the same bug; that comes from reading the patches. And when a model is given confident, wrong guidance about the cause, its fix rate collapses, from 65.0 percent with correct guidance to 15.2 percent with wrong guidance. Those two figures are grader output, so the exact values inherit the 65.9 percent problem, but a fifty-point swing survives a grader that is wrong one time in three. Both are useful to anyone deploying these tools. Neither was turned into the 1Password headline.

The paper offers no human baseline. Its only human comparison is a remark in Section 4.1 that in the authors’ experience developers stand a good chance of catching wrong guidance, which is an impression, not a measurement. The 26 percent is compared to nothing.

The paper does measure humans, on two codebases, but doesn’t say baseline. The kernel maintainers shipped the off-by-one into mainline. The freenginx maintainers shipped a fix of their own in place of a Trail of Bits patch, and their fix carried a client-triggerable crash. On both codebases where a human fix can be checked, the first human fix was defective. The only measured human clean-fix rate in the paper is zero for two.

The violation

The European Commission’s Communication COM(2018) 236 defines disinformation as verifiably false or misleading information that is created, presented and disseminated for economic gain or to intentionally deceive the public, and may cause public harm.

The figures fit the definition.

They are verifiably wrong by Sections 4.4 and 4.9, and the check is reproducible from the dataset.

They were published to launch a commercial unit and placed with the trade press on the day of release.

Security is a named public good under the definition, and the figures are already informing policy: Adrian Sanabria advised against AI patching on their strength five days after publication.

The 2018 Code of Practice excludes reporting errors. A reporting error would mean the reporter missed something, made a mistake. These authors recorded the defect on page 20 and then published the figure on page 1 to mint headlines related to their profit from it.

Background

1Password sells trust. Its VP of Product, Jason Meller, wrote honest.security, and the company still publishes it as the principles of its Device Trust product. I documented last week what those principles are worth.

Eleven days after DHH published a white supremacist screed “As I remember London,” Meller, a sitting Rails Foundation director beside DHH and Shopify, defended him for it. He wrote that he had become a multi-millionaire thanks to Rails, DHH and the company DHH keeps, and told readers to ignore the “noise” (backlash to white supremacist screed). Seven weeks after DHH published a Nazi memo called “The will to power will return,” and six weeks after DHH framed the Romani as a Nazi would, Meller called DHH’s year a masterclass in the “force of will” needed to change things, echoing DHH’s own Nazi phrase. On August 31, 1Password’s name appeared on the patron list of DHH’s Omacom Foundation.

That is the same company, in the same month, launching a research lab whose first paper published figures its own authors had shown were wrong.

The pattern of being wrong for profit is the point. The lab graded its patches with the models under test. The VP boosted his patron by calling widespread backlash to their Nazism just noise. In each case it’s a self-check, and in each case the evidence against them was already written down when their false claim went out.

A company that behaves this way about its own research and its own money is telling you it can not be trusted.

The filing

This is a civil matter. COM(2018) 236 defines a term, the Code of Practice is voluntary, the Digital Services Act binds platforms, and §263 StGB requires a deceived victim with a measured loss. The UWG applies. §5 covers misleading statements about the results of product tests, §5a covers misleading omission, and §6 requires comparative advertising that names competing products to rest on objective, verifiable characteristics.

The paper names Claude Opus 4.8 and ChatGPT 5.5 and publishes ten tables broken out by product after disclaiming any comparison in Section 2.1. Therefore the standing belongs to competitors, which means Anthropic and OpenAI under both the UWG and the Lanham Act, as well as the Wettbewerbszentrale in Bad Homburg and the FTC, each of which accepts complaints from anyone.

I am filing and you should too.

The authors documented the defect before the press release went out. The complaint rests on their behavior, their chosen sequence.

This Day in History 1942: Gestapo Arrest American Mildred Fish-Harnack

On this day, as we watch Elon Musk celebrate his work to push the AfD party into restoring Nazi power over Germany, we remember eighty-four years ago the Gestapo arrived in Preil, an Prussian fishing village, and arrested Mildred Fish-Harnack and her husband Arvid.

The couple were on their holiday.

AfD federal leader Alice Weidel celebrating the party's election result in the German state of Saxony-Anhalt. Elon Musk replying to her in German: Well done!
Source: Twitter

She was from Milwaukee. At the University of Wisconsin she edited the literary magazine and taught in the English department, where in 1926 she met Arvid Harnack, a Rockefeller fellow who had come to study labor economics with John R. Commons. They married that August. She joined him in Germany in 1929, taught American literature at Berlin University, and finished her doctorate at Giessen at the end of 1941.

Mildred Harnack
Arvid and Mildred Harnack

The Harnacks built one of the earliest resistance circles in Berlin out of an economics study group. With Harro and Libertas Schulze-Boysen and Adam and Greta Kuckhoff they documented Nazi crimes, printed leaflets, moved people out of the country, and passed intelligence on war preparations to the American embassy and to Soviet contacts. Arvid gave advance warning of Barbarossa.

An AfD poster is peeled off to reveal a Nazi flag

The Gestapo later filed all of their work against Hitler under one name, Rote Kapelle.

The Nazis had found them via radio. In July 1942 German military decryption read a Moscow transmission from the previous summer that carried Berlin addresses. Schulze-Boysen was arrested at the Air Ministry on August 31.

The Harnacks had only a week left.

The Reichskriegsgericht sentenced Arvid to death on December 19, 1942 and hanged him at Plötzensee three days later.

Mildred received six years. Hitler stepped in and invalidated the judgment on December 21 and ordered a kangaroo trial, which delivered the death sentence on January 16, 1943. She was beheaded at Plötzensee on February 16, 1943, the only American woman executed on his direct order.

She spent her final months translating Goethe into English. The last poem was finished on the day she died.

Her last recorded words:

Und ich habe Deutschland so geliebt.

The AFD (Nazi) party rally in Germany was headlined by the Tesla CEO
AfD Spitzenkandidat Ulrich Siegmund, expecting to become Ministerpräsident of Saxony-Anhalt, replying to Musk:

Thank you, @elonmusk, for your support and for your clear and highly important perspective on the political developments of our time — including here in Germany.
If we take responsibility here, I would very much welcome the opportunity for strong and constructive cooperation. Germany would once again be a place worth investing in.
Best regards from Saxony-Anhalt!
Source: Twitter

See the German Resistance Memorial Center biography and my 2012 post on the arrest.

Die AfD und die Berliner Datenpanne: Alles Wurst

English | Deutsch

Freitag, 15:35 Uhr. Der Erpressungs-Countdown von Rhysida lief ab, und 1.439.893 Dateien aus zwei Berliner Senatsverwaltungen landeten im Internet (via Tor). Personalakten, Geburtsurkunden von Kindern, 80.000 Bußgeldverfahren und 8.110 Dokumente zur kritischen Infrastruktur, darunter eine Schwachstellenanalyse der Berliner Wasserversorgung. Der Regierende Bürgermeister und seine Innensenatorin verbrachten den Abend entspannt bei der Basketball-WM.

Bis Sonntagnacht war ein zweites Datenpaket draußen, diesmal mit Zugangsdaten, und die Bauverwaltung schränkte den Zugriff auf ihre Fachverfahren zum dritten Mal seit dem 14. August ein. Wer es veröffentlicht hat, will der Senat noch nicht sagen.

Am selben Freitagnachmittag brachte die AfD Kristin Brinkers 100-Tage-Programm für die Führung der Stadt heraus. Nach wochenlangen Schlagzeilen über den Zustand der Informationssicherheit in Berlin fielen ihr vierzehn Punkte ein.

Im Kern sagte sie: Die Überwachung muss massiv ausgeweitet werden, riesige Datenmengen müssen erhoben werden, mit Kameras an Kriminalitätsschwerpunkten und an Mülltonnen. Richtig gelesen, Kameras an Mülltonnen. Sie will Polizeikontrollen ohne jeden Anlass oder Verdacht. In der Ausländerbehörde soll eine Sondereinheit der Polizei entstehen. Daten sollen außerdem mit einer Punkteakte über jeden Bewerber für eine landeseigene Wohnung erzeugt werden. Alles, restlos alles davon häuft mehr und mehr Daten in den Händen des Staates an. Nichts davon erwähnt allerdings die Schlagzeilen über das Landesnetz, das gerade 1,4 Millionen Dateien verloren hatte.

Am Samstag äußerte sich Brinker dann doch noch zu dem Datenleck, das ihr 100-Tage-Plan ignoriert hatte:

Der Daten-GAU zeigt aber auch, dass der Datenhunger des Staates eingehegt werden muss.

Sie beklagt also, dass der Staat zu viele Daten sammelt. Einen Tag nachdem sie beklagt hatte, dass der Staat nicht genug Daten sammelt.

Wer die Pressestelle der AfD am Freitag und dann am Samstag liest, dem sei verziehen, wenn er denkt, diese Leute wollen gar nicht gewinnen, weil sie dann für etwas stehen müssten und nicht mehr einfach alles angreifen könnten, was alle anderen sagen.

Der Datenhunger des Staates

Der Staat sollte sich nicht zur Totalüberwachung ausdehnen, und der Staat sollte nicht in totale Ahnungslosigkeit zusammenfallen. Das sind die Extreme, die die extremistische AfD vor sich herträgt, während in Wirklichkeit die ausgewogene Mitte der richtige Weg ist. Die Dateien im Leak sind Geodaten, die jedes Bezirksamt herausgibt, Bußgelder, die der Staat gesetzlich aufbewahren muss, Verträge, die er vorhalten muss, Personalakten, die er führen muss, und Risikoanalysen zur kritischen Infrastruktur, die das Bundesrecht den Wasserbetrieben vorschreibt, damit sie wissen, wo man sie brechen kann. Wer so dumm wäre, sich für die Samstagsversion der AfD zu entscheiden, bei dem wird die Betriebskarte der kritischen Wasserinfrastruktur nie fertig, und das Wasser ist gefährdet. Brinker meint, Daten müssen für die Sicherheit gesammelt werden, und auch, dass Daten für die Sicherheit nicht gesammelt werden dürfen. Das belegt, dass sie Sicherheit nicht versteht, und dass sie für die Worte, die sie benutzt, nicht geradestehen will.

Noch einmal: Sie hatte drei Wochen Vorlauf zum Angriff und eine Woche Vorlauf zum Leak, und sie legte ihren großen Plan für Berlin ohne ein Wort zur Informationssicherheit vor. Der Countdown war seit dem 28. August öffentlich. Sie kannte den Termin und verpasste ihn vollständig, veröffentlichte an diesem Tag ein unvollständiges Regierungsprogramm, ohne es zu bemerken, und verrenkte sich dann am Samstag zur Brezel, um so auszusehen, als wäre es ihr wichtig.

Wie Berlin versagt hat

Lassen wir die Ahnungslosigkeit der AfD beiseite. Das eigentliche Problem, jenseits der Daten selbst, ist, wie Berlin das Team zur Erkennung und Abwehr von Angriffen abgebaut hat, während das Angriffsrisiko gestiegen ist.

Im November 2024 kürzte die schwarz-rote Koalition den Etat für das Landesnetz von 32 auf 18 Millionen Euro und strich 2 Millionen gezielt bei der Eindringungserkennung. Ja, sie kürzten das Budget, mit dem Angriffe erkannt werden. Die Chefin des landeseigenen IT-Dienstleisters, Maria Borelli, sagte dem Digitalisierungsausschuss, was das bedeutet:

Es entsteht das Risiko von Cyberangriffen oder Fehlern.

Sie fügte hinzu, dass die Finanzverwaltung den Überschuss ihres Hauses gegen das Votum ihres eigenen Verwaltungsrats in den Landeshaushalt zog, sodass sie nicht investieren konnte, um die Substanz zu erhalten. Manuel Atug, Berater für die Sicherheit kritischer Infrastrukturen, hatte dem Innenausschuss schon zweimal gesagt:

Ihr betreibt desolate Cybersicherheit.

Die Linke widersprach zu Protokoll. Sonst niemand. Daraus lässt sich ablesen, welche Partei den Sicherheitshaushalt gelesen hat.

Zwanzig Monate später brauchte Rhysida fünf Tage, vom 7. bis 12. August, um zwei Senatsverwaltungen leerzuräumen. Kein Alarm ging los. Das Sicherheitsteam des Dienstleisters bemerkte es zufällig, an auffälligem Verkehr in Verwaltungen außerhalb seiner Zuständigkeit, zwei Tage nachdem die Daten weg waren. Genau das Ergebnis, das Borelli dem Ausschuss vor der Kürzung beschrieben hatte.

Es lohnt der Blick darauf, wie andere Länder sich anders entschieden haben. Bayern schuf 2017 ein Landesamt für Sicherheit in der Informationstechnik mit gesetzlichem Auftrag über das gesamte Behördennetz: die Protokolldaten jedes Sicherheitselements in ein zentrales SIEM, Verdachtsfälle an ein Cyber Defence Center, dazu eine Beratungspflicht für Kommunen und landeseigene Versorger. Ein Wasserversorger ist dort von Amts wegen Kunde.

Berlin betreibt seine Sicherheit als Geschäftsfeld in einem Unternehmen, das Überschüsse erwirtschaften soll, besteuerte dann die Überschüsse und verteilte die Verantwortung auf den Dienstleister, einen Beauftragten in der Senatskanzlei, einen Sicherheitsbeauftragten in jeder Verwaltung und zwölf Bezirke, von denen einer, Lichtenberg, am Sonntag beschloss, CrowdStrike, dem US-Unternehmen, das der Senat nach dem Angriff mit der Schadensanalyse beauftragt hat, jeden Zugang zu seinen Servern zu verweigern. Das Land, das sein eigenes Erkennungsbudget gekürzt hat, mietet jetzt Erkennung bei einem US-Konzern (bekannt für seine Politik und seine Verbindungen zum FBI) in Reichweite des CLOUD Act, und bekommt ihn in seinen eigenen Bezirken nicht installiert.

Nach der Bestandsaufnahme einer Arbeitsgemeinschaft der Linken weiß das Land nicht einmal, wie viele Fachverfahren im Netz laufen. Ein Staat, der Inventar und Asset Management nicht beherrscht, und das ist Schritt eins, kommt nicht zu Prävention und Erkennung, weil er noch gar nicht versteht, was er vor sich hat.

Auf den Tag genau ein Jahr vor dem Leak teilte der Senat den Grünen mit, vergleichbare Angriffe seien “nicht bekannt” und die Zuständigkeit für die Cyberabwehr werde noch evaluiert. Nicht bekannt heißt: Fehlen von Belegen, nicht Beleg des Fehlens.

Wen nimmt die AfD jetzt ins Visier

Stefan Evers, Finanzsenator seit 2023 und jetzt Spitzenkandidat der CDU für das Rote Rathaus. Sein Haus kürzte das Erkennungsbudget, kassierte den Überschuss des Dienstleisters und hält die Landesbeteiligung an den Wasserbetrieben, deren Prüfung von 2020 acht kritische und neun hohe Schwachstellen fand, die Firewalls “fehlerhaft, lückenhaft und nicht nachvollziehbar”, Gesamtnote mangelhaft. Zehn sollten bis zum Juli jenes Jahres behoben sein. Sieben wurden nie öffentlich abgeschlossen. Ein IFG-Antrag auf den Prüfbericht, gestellt am 31. Juli 2020, steht bis heute auf “Antwort ausstehend”. Jetzt liegt die Landkarte dieser ganzen Verschleppung im Internet.

Iris Spranger, Inneres, die Atug zweimal gehört hat. Florian Hauer, Chief Digital Officer, der dem Parlament in nichtöffentlicher Sitzung nicht sagen konnte, wann der Angriff stattfand oder ob er vorbei war. Kai Wegner, der am 19. August erklärte, es seien keine sensiblen Daten abgeflossen. Brinkers Angriffsformel “Wegner hat gelogen” ist zwar richtig, aber es ist auch das, was dpa am Freitag unter “grobe Fahrlässigkeit” verbreitet hat. Sie kam einen Tag zu spät und sagte “erneut”.

Ihre eigene Bilanz widerspricht dem Rezept, das sie jetzt vorschlägt. Ihre jüngsten parlamentarischen Anfragen drehen sich um die Kürzung der Personalausgaben des Landes, um die Prüfung von Journalisten durch die Medienanstalt und um NGO-Förderung. In der Antwort des Senats zu den Personalausgaben steht, dass die Verkehrsverwaltung wegen des Cyberangriffs nicht antworten konnte. Der Angriff stand Wochen vor dem Leak in ihren eigenen Unterlagen. Ich kann es nicht deutlich genug sagen: Es gibt keinerlei Beleg, dass sie irgendetwas nachgefragt oder irgendeine Idee entwickelt hätte. Es ist erschütternd, wie wenig es sie zu kümmern schien.

Wer den Berlinern dient

Die Grünen forderten ein Portal, auf dem Bürger prüfen können, ob sie im Leak stehen. Der Senat sagt, die Benachrichtigung erfolge “risikobasiert”, ansonsten gebe es ein Webformular. Der Rhein-Pfalz-Kreis, 2022 von einer vergleichbaren Gruppe getroffen, hat innerhalb von drei Wochen 2.549 individuelle Briefe verschickt. Berlin, vier Jahre später und mit einem Haushalt von 45 Milliarden Euro, verweist auf ein Formular, das für Fahrraddiebstähle gebaut wurde.

Linke und Grüne haben die Sitze, um einen Untersuchungsausschuss zu erzwingen, werden ihn aber vor der Wahl nicht beantragen, weil jede Koalition danach über die SPD läuft, die das Innenressort führte, während all das geschah. Brinker wird ihn auch nicht beantragen. Eine Anhörung darüber, welche Schritte Minute für Minute in den Netzwerkprotokollen unternommen wurden, ist der Ort, an dem eine “Sicherheitspartei”, die für nichts steht, zugrunde geht.

Der Angriff beweist nicht, dass Berlin zu viele Daten gesammelt hat. Er beweist, dass Berlin aufgehört hat, für die Überwachung dessen zu bezahlen, was es von Gesetzes wegen wissen muss, öffentlich gewarnt wurde und trotzdem das Falsche tat. Das hat Namen: Evers, Spranger, Hauer, Wegner.

Brinkers Kehrtwende von Freitag auf Samstag beweist, dass die AfD dieses Versagen zu immer höheren Kosten wiederholen wird. Ihre Kameras, Kontrollen und Wohnungsakten sind genau die Daten, die Angreifer wollen. Ihr Plan schiebt sie in ein Netz, für dessen Absicherung sie keinen Plan hat. Wenn das Problem die Daten sind, sollte die AfD nicht damit antreten, die meisten Daten zu sammeln und am wenigsten für ihren Schutz zu tun.

Linke und Grüne sollten den Untersuchungsausschuss sofort beantragen und die Koalition erklären lassen, warum er warten soll. Der Senat sollte veröffentlichen, wie viele Daten zwischen dem 7. und 12. August das Netz verlassen haben und wie es um die sieben offenen Befunde bei den Wasserbetrieben steht, oder eingestehen, dass er es nicht kann. Und jede Kandidatin und jeder Kandidat für das Rote Rathaus sollte öffentlich eine Frage beantworten müssen: Stellen Sie die Eindringungserkennung im Landesnetz wieder her, und mit wie viel Geld? Brinker hat schon bewiesen, dass sie es weder will noch kann. Sie hat vierzehn Punkte herausgehauen, und nicht ein einziger schützt vor einem Cyberangriff.