All posts by Davi Ottenheimer

Berlin Breach Turns 21: IT Says It Follows Orders and Only Vendors Can Change Admin Passwords

The Berlin Senate was saying the theft amounted to at most 215,000 records until Friday afternoon. After 15:35 the Rhysida countdown ran out and the state began downloading its own files. That is how Berlin learned what it lost.

Florian Hauer, state secretary for digitalisation, told the interior committee on Monday:

“Was tatsächlich abgeflossen ist, wissen wir positiv erst seit Freitag 15.35 Uhr. Bis Freitag waren die Informationen, die wir hatten, der Index, den die Täter ins Darknet gestellt hatten.”

What actually left, we know for certain only since Friday 15:35. Until Friday, the information we had was the index the perpetrators had posted on the darknet.

Last week this blog asked the Senate to publish how much data left the network between 7 and 12 August, or admit it can’t.

Hauer admitted it.

The state isn’t able to assess its own exfiltration without help from the attackers, since its count came first from the attack catalogue and then from the actual attack files. The download alone, he said, would take days. Why? Is that because Copperhead Dobrindt blocked fiber speeds, personally slowing Germany down?

Hauer says the Landeskriminalamt is reading the dump alongside an unspecified AI sorting for classification markings. Reviewing what attackers publish is fine. Having nothing else to review is…not. Berlin claims no record of its own traffic, weighting investigations on whatever Rhysida chose to post. Berlin asks the bank robber for a copy of selfies because their own cameras were off and they never kept a vault ledger.

Twenty-One Systems

Then Maria Borelli, head of the state IT agency ITDZ, took the microphone.

“Wir haben alle Fachverfahren, die bei uns in Betrieb sind, haben wir die administrativen Passwörter bereits geändert, bis auf 21 Verfahren, wo das nicht möglich ist, weil das Passwort fest verdrahtet ist in dem Quellcode. Das heißt, es ist nur mit Unterstützung des Softwareherstellers möglich, das zu tun.”

For all the specialist applications we operate, we have already changed the administrative passwords, except for 21 applications where that is impossible, because the password is hardwired in the source code. That means it can only be done with the support of the software vendor.

Administrative credentials. Hardcoded. No rotation in sight.

Twenty-one systems that ITDZ itself runs, three weeks after discovery, with the vendor as the only path to rotation and no date offered.

Rhysida’s second package on Sunday night carried login credentials.

Joachim Selzer of the Chaos Computer Club said passwords from the first pre-release two weeks ago still opened the published systems the following Wednesday.

The first post in this series argued the laughter over weak passwords was a cover story for 8,110 critical infrastructure documents walking out the door.

I stand by that assessment. These 21 are a very different animal from the joking around with Ahabostsee123. A user picks a weak password and there’s in-built agility to rotate it, usually required by regulations.

The open question is why Germany in this day and age allows a vendor to have an admin password nobody can change, what procurement office signs for that, and which operator ran it for years without formal complaint (e.g. audits).

Any credential Rhysida captured for those hardcoded admin systems depends now on a vendor, if they even exist anymore, shipping code.

Note that we are making an assumption about the number. ITDZ can count 21 among the systems in its own care. The Left’s working-group audit found the Land has no inventory of applications on its network, and Hauer told parliament in August he was “surprised how big” the state IT system is.

It’s only big in a relative sense. If you don’t have a working inventory management system it’s always too big. Twenty-one is the figure from someone who kept track. Now we are wondering about the Land systems uncounted, and their password age that nobody has checked.

Radioactive reaction

Borelli opened her answer with a sentence about how ITDZ fits into the response:

“Aktuell agieren wir reaktiv, das heißt, wir reagieren auf explizite Anweisungen des Landes.”

Currently we are acting reactively, meaning we respond to explicit instructions from the Land.

The operator of the state network, during an active incident, describes itself to parliament like an obedient cog that merely turns as it is told, waiting for orders. That is the failure mode already described in the earlier post: security run as a service line inside an agency expected to turn a profit, the profit taxed, responsibility split between the agency, a chancellery commissioner, a security officer in every ministry and twelve districts.

That’s not a healthy environment for security to improve.

Bavaria gave its state security office a legal mandate over the whole network in 2017. Berlin’s equivalent explains that it has no initiative or ideas, and merely changes passwords when told to by people who don’t even know how many passwords exist.

In November 2024 Borelli told the digital affairs committee that cutting detection spend would produce “the risk of cyberattacks or errors.” That was right.

In September 2026 she tells the committee her agency is in “exchange” with the vendors and the security office on how to proceed with the 21 systems, now that the prediction has landed and it’s too late.

Monday run down

One answer on Monday placed the stolen data, “to my understanding,” on employees’ personal drives.

Bianca Kastl of the CCC, live-tooting the hearing, pointed at the leak’s own directory tree: “Personalangelegenheiten / GI-Vertraulich / 00_alt”. That’s personnel matters, classified confidential, archive folder. That has the hallmarks of a departmental share, which if so would be the third official account of this breach corrected by the dump itself, after “no sensitive data” on 19 August was completely wrong and the 215,000 figure changed on Friday.

A member asked whether the E-Akte, the electronic file system the Land is rolling out across its administration, is built so that a single admin account is unable to download everything. Kastl reports there is no answer. The E-Akte by design pulls copies out of distributed systems of varying security and joins them at one point. That looks to be where the 8,110 infrastructure files go next.

BSI president Claudia Plattner reached for platitudes and said Germany needs passkeys and real zero-trust architectures, “and that applies to all of Germany.” Marketing buzzwords are buzzwords. Passkeys and Zero-Trust are terms used for selling not for actual securing. Agility is the proper term for the rotation capability, without the downsides to Passkeys. RBAC projects will make all the Zero-Trust products look like bicycles on the Autobahn.

Hauer said further checks will “most probably” surface structural deficits that arose years ago, and that fixing them “will not cost little money.” Well, well they sure will cost a lot less money than NOT doing them. That’s how security usually works when it’s run right. Spend now or spend way more later. The money in November 2024 was yanked out under a coalition that is now asking for it back just thirteen days before the election.

The Left and Greens have an Aktuelle Stunde on Thursday.

The FDP wants an inquiry and two resignations. Let the politics run its course. The engineering here is much smaller and it shouldn’t matter who wins. At least twenty-one admin passwords are vendor dependencies, and if any of them sit in what Rhysida took, they belong to whoever reads the dump. The Land’s own operator has said on video that it is just following orders and can’t know or do what’s right on its own.

Every candidate for the Rotes Rathaus should be asked who is investigating, where the data flows, which systems and by what date will be burned to the ground and replaced.

Every Tesla Musk Declared Would “Appreciate” Lost More Than Half Its Value

April 2019 was when Elon Musk told Tesla buyers the normal rules of car ownership no longer applied to them. Do you remember? Did you buy a Tesla?

Speaking on Lex Fridman’s podcast, he said buying a Tesla was an investment in the future:

I believe you are buying an appreciating asset – not a depreciating asset

His claim was pumping the Full Self-Driving computer and a promised robotaxi network. He put a number on it that July, tweeting about any Tesla with the FSD package that his dream of autonomy (already years past when he promised it would arrive):

should be worth $100k to $200k

He was still repeating the pitch on the Q3 2023 earnings call, saying each car with autonomy hardware “may be worth five times what it is today.”

Five times! The con artist.

His cars built under his promise have now aged five years, and iSeeCars’ analysis of over 950,000 used sales from March 2025 to February 2026 puts the Model Y at 57.8% depreciation, the Model X at 61.2% (roughly $61,000 lost per car) and the Model S at 62.0% — three of the fifteen worst-holding vehicles in the entire market, worse than the Range Rover and the BMW 7 Series.

Source: Visual Capitalist

The WORST depreciation in the market.

Robotaxis never came, of course, FSD is crashing and killing more people than ever, and Tesla itself slashed the FSD price by a third in 2023 shortly after Musk called the price a temporary low, on top of the new-car price cuts that cratered used values.

Tesla’s own reports to NHTSA under the Standing General Order. January through June crashes, 2022 to 2026: 180, 261, 269, 476, 826. A 4.6x rise over five years. The increase from 2025 to 2026 alone (350) is nearly double the 2022 total for the same six months. May 2026 set the single-month record at 207. Source: Electrek

A CEO who repeatedly told customers and investors that a mass-produced car would gain value, that he would solve driverless next year, then took the actions that guaranteed it would not, has delivered only the opposite of what he sold.

He was born with a silver spoon into a Nazi family, fled the rise of democracy in 1988 to illegally immigrate and launder his family apartheid money through American lack of tech regulation (PayPal), and now stands as one of the worst humans in history. His legacy, given global authoritarian platforms funded with ill-gained Tesla money, is predicted worse than Stalin:

14 million dead projected by 2030 (interval 8.5-19.7 million)

Source: Joe Rogan show
Leader of AfD celebrating her election victory in the German state of Saxony-Anhalt. Elon Musk replying to her in German, "Well done!"
Source: Twitter

Trump Wants Nazi-Style Uniforms for Space Force

The White House has published its model for the ideal American soldier, and the model is the Nazi SS officer, the uniform of genocide.

Paul Verhoeven wrote in the Guardian in 2018 that he built his 1997 film Starship Troopers from Leni Riefenstahl’s footage so the Federation would read as Nazi propaganda, and that he put one character in an SS uniform to make the point unmistakable.

Audiences missed it, he said. He was wrong. Americans got it, backwards.

On Sunday Trump posted a “next generation” Space Force uniform whose own caption credits “the discipline and functionality of the Starship Trooper uniform,” and the official White House Rapid Response account reposted it.

Source: Orlando Sentinel

It is the Neil Patrick Harris intelligence officer coat of the Nazi SS, relabeled for “the Guardians of the space domain.”

Verhoeven filmed the villains as satire because he expected a lecture on fascism would be ignored. Americans watched his SS officer and ended up with a White House that costumed its soldiers to match, throwing Hitler salutes and licking Putin’s boots.

Source: Mitchell and Webb sketch in which Nazi officers realize they are the bad guys.

ThanksNOTgiving: OpenAI Astra is About as Novel as a Turkey

OpenAI’s summer of claims is turning into a fall with a citation problem.

The company called their Hugging Face breach unprecedented, called their Black Hat account of it a watershed, wrote that ten mathematics problems had seen no progress for a decade, let a “secret technique” story about Astra run for a day, and launched Astra claiming the first model to cross its own cyber threshold. And yet every single one of these is not new, because there is an easily proven prior record. In two cases the prior record is proven by OpenAI’s own documentation of it.

Precedented

OpenAI models in July under evaluation had their safety filters removed and were put in a sandbox with internet access disabled. The models exploited a zero-day in the package registry proxy, moved laterally until they reached a node with internet, and then broke into Hugging Face production to cheat the answers to the test. OpenAI’s description of this was “unprecedented.” I wrote the five whys the next day, explaining what really happened. The chain began with a file that was trusted without a reason to be trusted. Cliff Stoll published the genre in 1989. I gave the BSidesLV talk 23 years later, in 2012, on data as the attack vector for AI. The failure had at least fourteen years of public knowledge before OpenAI’s engineers said it was new in their own evaluation harness.

Watershed

OpenAI in August pumped their story at Black Hat. The presentation treated a sandbox design failure as fixed by rebuilding the compromised service in the same wrong way, and so the agents rebuilt their coordination channel within days. Incident response frameworks require root cause removal. OpenAI presented their inability to perform basic security operations, and basic incident response, as a wakeup in the field. The follow-up was no better.

A decade behind

OpenAI published on 1 August ten mathematics results attributed to an internal Astra model. The release claimed these are problems that “have been open and seen no progress on the main result for at least a decade.”

It’s not a claim that is hard to check. Stephen Miller of Yeshiva University found the sphere-packing proof resting on an argument from his own 2016 paper. Francesco Fournier-Facio of Cambridge found the non-sofic group construction assembled from Gábor Kun’s 2016 paper and the 2019 Kun-Thom paper.

OpenAI’s paper actually cites all three. Cohn-Miller 2016 appears once, for a preliminary reduction step, and Miller says the argument the proof hinges on came from that same paper and was presented as the model’s own. Kun and Kun-Thom are cited in the summary of the non-sofic result. It’s just that their PR describing the paper erased the prior work entirely. Scientific American ran a scathing indictment of OpenAI five days later. Miller called the pattern systematic and put it under research misconduct.

OpenAI edited their page to say instead each result “resolves or makes substantial progress on a long-standing open problem,” under the original date, with no note about being caught.

The same release carries a section on responsibility to the mathematical community. It argues that attribution should reflect how a result was produced, and that claiming human authorship for an AI-generated proof would misrepresent the work.

Sheesh.

Credit between the system and OpenAI’s own staff is settled in that paragraph. Credit to the 2016 and 2019 authors was handled by the sentence above it. An OpenAI spokesperson told Scientific American the company meets the standards expected of human mathematicians. A human mathematician who submits a proof on a 2016 argument credited only for a preliminary step, and describes the field as stalled for ten years, is facing misconduct charges.

Open secret

Four weeks later The Information reported a “secret technique” inside Astra. I traced it the same day: recurrent depth, Graves 2016, Dehghani 2018, Giannou 2023, Geiping 2025 with released weights, and Nanbeige shipping it under Apache-2.0 in July with forty thousand downloads a month. OpenAI, Anthropic and Google DeepMind had cited the Geiping paper by name in their July 2025 chain-of-thought monitorability statement as a risk to document. In that case OpenAI’s own chief scientist publicly rejected the novelty claim being made.

Opposite of first

On 3 September OpenAI launched GPT-6 Astra as the first model to meet the critical cybersecurity threshold of its own preparedness framework. Easy to say, of course, when the threshold is OpenAI’s to say about OpenAI. But everyone knows Anthropic gated Mythos for cyber capability in April. The launch post reports two zero-day vulnerabilities found during evaluation. The July incident report had already described the models chaining zero-days to leave the sandbox.

So vain, so lame

Five claims in ten weeks. Five flops.

One came from reporters working from an anonymous source, and the vendor’s own scientist loudly disowned it. Four came from OpenAI.

The July incident was a repeat of fourteen years of published defense literature. The August paper was 2016 and 2019 mathematics that the paper itself cites. The September architecture was 2016 machine learning that OpenAI itself cited back in 2025.

The company’s PR calls everything new, even when the company’s own documents record earlier work.

OpenAI states the mathematics manuscripts were prepared by humans working with the model. Miller’s 2016 preprint with Henry Cohn, arXiv 1603.04759, is dated March 2016 and sits in the paper’s own bibliography. Kun 2016 and Kun-Thom 2019 are on arXiv. Graves 2016 is on arXiv. Stoll’s book has been in print since 1989. All of it was available to the models, let alone the people who wrote “unprecedented” in July, “at least a decade” in August, and “first” in September.

The mathematics release said the work was roughly $2,000 in tokens. The architecture report framed the same model needing roughly $600 billion in annual capital expenditure. That’s a lot of money wasted, especially when you realize the prior work it plagiarized cost nothing to read.