Category Archives: Security

RAIV in Berlin Says the Senate Has Time for Breach Triage

Berlin’s Chief Digital Officer told the Innenausschuss that “AI tools” will rank more than 1.2 million leaked files by risk; the published archive runs to 1.44 million. People have opinions about this nod to AI, of course, including me.

However, he gave us no location and no one asked him the obvious questions, so here we go.

All we are talking about is document classification. A model reads a file and says: personal data, credentials, court record, infrastructure drawing, contract, noise. Open-weight models that anyone can download today do this very well for free. The harness around the model actually does the real work: extract text, regex the obvious identifiers, run a fixed rubric, log everything, hand the top tier to humans.

I’ve written and published on exactly this extensively, not to mention published tools.

Berlin Loves a Good RAIV

Last week I published the RAIV, a Redundant Array of Inexpensive Videocards: seven used AMD MI50 cards at 220 euros each on a secondhand EPYC board, two mirrored groups of three plus a hot spare, 192 GB of VRAM, about 3,500 euros all told. It’s familiar if you built large storage in the 1990s, so a dead card loses one job if that and the run lives. I’m calling this one the Berlin RAIV because I’m terrible at marketing and don’t care. More important is that it runs a 100B-class open model at four-bit per mirror, or a 20B-class classifier on every card in parallel, which is what this job calls for.

Sail Time

A classifier needs the first thousand tokens of a document plus the regex hits, so budget 1.5 billion tokens for the archive. An MI50 pushing a 20B sparse model through llama.cpp prefills on the order of 500 tokens a second, conservatively. We have six cards, 3,000 a second, so six days per rig. Ten of these Berlin RAIVs run the full archive in under a day of model time and cost 35,000 euros, or less depending on used-parts dealers this week (and the inevitable rush of squatters). Extracting and OCRing 5.8 terabytes is CPU work and takes longer. Two weeks should be enough, including human review of the most sensitive files. The Senate has spent three weeks explaining why it has no time, which should have been used instead for real forensics work.

Rhysida asked for two million. I’m saying ten rigs of used AMD cards shows them a middle finger for less than the Senatsverwaltung’s annual caffeine budget.

That’s just the hard reality in tech terms. Now the fluff of politics.

Batten the Hatches

The archive contains civil defence plans, Kasernen documents, and detail drawings of water works, substations and emergency power. Letting any of that flow to a US service lands under the CLOUD Act, which compels the provider to hand data to US authorities on request wherever the server sits. The Senate would be duplicating Berlin’s infrastructure vulnerabilities inside a particular foreign jurisdiction (hiring Nazis) in order to find out how bad the first copy was. Rhysida at least stole it. The Senate would be donating it to the bad guys.

In 1938 Roosevelt had a Nazi spy ring operating out of New York, the Rumrich case. He had the FBI arrest it, try it, and convict it. He did not phone Berlin and ask the Gestapo to send its people to make it easier on Americans. The Bezirk Lichtenberg understood this and refused the Senate’s anti-hacker software over data access. The Senate has yet to catch up with its own Bezirk.

Germany can do this. It needs to pivot to a science-based response, reducing its dependency on mythological methods.

The cards are the real recycling deal. The models are public. The skills are here; the CCC has been describing the response in the open for three weeks, and a RAIV is a weekend build.

Any politician who says “we had no time” and ships this archive across the Atlantic is choosing the one option that makes the German national security damage even larger and more permanent.

My ask for the Thursday group is one sentence: which tool, where does it run, and who gets that ranked list?

Berlin Breach Turns 21: IT Says It Follows Orders and Only Vendors Can Change Admin Passwords

The Berlin Senate was saying the theft amounted to at most 215,000 records until Friday afternoon. After 15:35 the Rhysida countdown ran out and the state began downloading its own files. That is how Berlin learned what it lost.

Florian Hauer, state secretary for digitalisation, told the interior committee on Monday:

“Was tatsächlich abgeflossen ist, wissen wir positiv erst seit Freitag 15.35 Uhr. Bis Freitag waren die Informationen, die wir hatten, der Index, den die Täter ins Darknet gestellt hatten.”

What actually left, we know for certain only since Friday 15:35. Until Friday, the information we had was the index the perpetrators had posted on the darknet.

Last week this blog asked the Senate to publish how much data left the network between 7 and 12 August, or admit it can’t.

Hauer admitted it.

The state isn’t able to assess its own exfiltration without help from the attackers, since its count came first from the attack catalogue and then from the actual attack files. The download alone, he said, would take days. Why? Is that because Copperhead Dobrindt blocked fiber speeds, personally slowing Germany down?

Hauer says the Landeskriminalamt is reading the dump alongside an unspecified AI sorting for classification markings. Reviewing what attackers publish is fine. Having nothing else to review is…not. Berlin claims no record of its own traffic, weighting investigations on whatever Rhysida chose to post. Berlin asks the bank robber for a copy of selfies because their own cameras were off and they never kept a vault ledger.

Twenty-One Systems

Then Maria Borelli, head of the state IT agency ITDZ, took the microphone.

“Wir haben alle Fachverfahren, die bei uns in Betrieb sind, haben wir die administrativen Passwörter bereits geändert, bis auf 21 Verfahren, wo das nicht möglich ist, weil das Passwort fest verdrahtet ist in dem Quellcode. Das heißt, es ist nur mit Unterstützung des Softwareherstellers möglich, das zu tun.”

For all the specialist applications we operate, we have already changed the administrative passwords, except for 21 applications where that is impossible, because the password is hardwired in the source code. That means it can only be done with the support of the software vendor.

Administrative credentials. Hardcoded. No rotation in sight.

Twenty-one systems that ITDZ itself runs, three weeks after discovery, with the vendor as the only path to rotation and no date offered.

Rhysida’s second package on Sunday night carried login credentials.

Joachim Selzer of the Chaos Computer Club said passwords from the first pre-release two weeks ago still opened the published systems the following Wednesday.

The first post in this series argued the laughter over weak passwords was a cover story for 8,110 critical infrastructure documents walking out the door.

I stand by that assessment. These 21 are a very different animal from the joking around with Ahabostsee123. A user picks a weak password and there’s in-built agility to rotate it, usually required by regulations.

The open question is why Germany in this day and age allows a vendor to have an admin password nobody can change, what procurement office signs for that, and which operator ran it for years without formal complaint (e.g. audits).

Any credential Rhysida captured for those hardcoded admin systems depends now on a vendor, if they even exist anymore, shipping code.

Note that we are making an assumption about the number. ITDZ can count 21 among the systems in its own care. The Left’s working-group audit found the Land has no inventory of applications on its network, and Hauer told parliament in August he was “surprised how big” the state IT system is.

It’s only big in a relative sense. If you don’t have a working inventory management system it’s always too big. Twenty-one is the figure from someone who kept track. Now we are wondering about the Land systems uncounted, and their password age that nobody has checked.

Radioactive reaction

Borelli opened her answer with a sentence about how ITDZ fits into the response:

“Aktuell agieren wir reaktiv, das heißt, wir reagieren auf explizite Anweisungen des Landes.”

Currently we are acting reactively, meaning we respond to explicit instructions from the Land.

The operator of the state network, during an active incident, describes itself to parliament like an obedient cog that merely turns as it is told, waiting for orders. That is the failure mode already described in the earlier post: security run as a service line inside an agency expected to turn a profit, the profit taxed, responsibility split between the agency, a chancellery commissioner, a security officer in every ministry and twelve districts.

That’s not a healthy environment for security to improve.

Bavaria gave its state security office a legal mandate over the whole network in 2017. Berlin’s equivalent explains that it has no initiative or ideas, and merely changes passwords when told to by people who don’t even know how many passwords exist.

In November 2024 Borelli told the digital affairs committee that cutting detection spend would produce “the risk of cyberattacks or errors.” That was right.

In September 2026 she tells the committee her agency is in “exchange” with the vendors and the security office on how to proceed with the 21 systems, now that the prediction has landed and it’s too late.

Monday run down

One answer on Monday placed the stolen data, “to my understanding,” on employees’ personal drives.

Bianca Kastl of the CCC, live-tooting the hearing, pointed at the leak’s own directory tree: “Personalangelegenheiten / GI-Vertraulich / 00_alt”. That’s personnel matters, classified confidential, archive folder. That has the hallmarks of a departmental share, which if so would be the third official account of this breach corrected by the dump itself, after “no sensitive data” on 19 August was completely wrong and the 215,000 figure changed on Friday.

A member asked whether the E-Akte, the electronic file system the Land is rolling out across its administration, is built so that a single admin account is unable to download everything. Kastl reports there is no answer. The E-Akte by design pulls copies out of distributed systems of varying security and joins them at one point. That looks to be where the 8,110 infrastructure files go next.

BSI president Claudia Plattner reached for platitudes and said Germany needs passkeys and real zero-trust architectures, “and that applies to all of Germany.” Marketing buzzwords are buzzwords. Passkeys and Zero-Trust are terms used for selling not for actual securing. Agility is the proper term for the rotation capability, without the downsides to Passkeys. RBAC projects will make all the Zero-Trust products look like bicycles on the Autobahn.

Hauer said further checks will “most probably” surface structural deficits that arose years ago, and that fixing them “will not cost little money.” Well, well they sure will cost a lot less money than NOT doing them. That’s how security usually works when it’s run right. Spend now or spend way more later. The money in November 2024 was yanked out under a coalition that is now asking for it back just thirteen days before the election.

The Left and Greens have an Aktuelle Stunde on Thursday.

The FDP wants an inquiry and two resignations. Let the politics run its course. The engineering here is much smaller and it shouldn’t matter who wins. At least twenty-one admin passwords are vendor dependencies, and if any of them sit in what Rhysida took, they belong to whoever reads the dump. The Land’s own operator has said on video that it is just following orders and can’t know or do what’s right on its own.

Every candidate for the Rotes Rathaus should be asked who is investigating, where the data flows, which systems and by what date will be burned to the ground and replaced.

Every Tesla Musk Declared Would “Appreciate” Lost More Than Half Its Value

April 2019 was when Elon Musk told Tesla buyers the normal rules of car ownership no longer applied to them. Do you remember? Did you buy a Tesla?

Speaking on Lex Fridman’s podcast, he said buying a Tesla was an investment in the future:

I believe you are buying an appreciating asset – not a depreciating asset

His claim was pumping the Full Self-Driving computer and a promised robotaxi network. He put a number on it that July, tweeting about any Tesla with the FSD package that his dream of autonomy (already years past when he promised it would arrive):

should be worth $100k to $200k

He was still repeating the pitch on the Q3 2023 earnings call, saying each car with autonomy hardware “may be worth five times what it is today.”

Five times! The con artist.

His cars built under his promise have now aged five years, and iSeeCars’ analysis of over 950,000 used sales from March 2025 to February 2026 puts the Model Y at 57.8% depreciation, the Model X at 61.2% (roughly $61,000 lost per car) and the Model S at 62.0% — three of the fifteen worst-holding vehicles in the entire market, worse than the Range Rover and the BMW 7 Series.

Source: Visual Capitalist

The WORST depreciation in the market.

Robotaxis never came, of course, FSD is crashing and killing more people than ever, and Tesla itself slashed the FSD price by a third in 2023 shortly after Musk called the price a temporary low, on top of the new-car price cuts that cratered used values.

Tesla’s own reports to NHTSA under the Standing General Order. January through June crashes, 2022 to 2026: 180, 261, 269, 476, 826. A 4.6x rise over five years. The increase from 2025 to 2026 alone (350) is nearly double the 2022 total for the same six months. May 2026 set the single-month record at 207. Source: Electrek

A CEO who repeatedly told customers and investors that a mass-produced car would gain value, that he would solve driverless next year, then took the actions that guaranteed it would not, has delivered only the opposite of what he sold.

He was born with a silver spoon into a Nazi family, fled the rise of democracy in 1988 to illegally immigrate and launder his family apartheid money through American lack of tech regulation (PayPal), and now stands as one of the worst humans in history. His legacy, given global authoritarian platforms funded with ill-gained Tesla money, is predicted worse than Stalin:

14 million dead projected by 2030 (interval 8.5-19.7 million)

Source: Joe Rogan show
Leader of AfD celebrating her election victory in the German state of Saxony-Anhalt. Elon Musk replying to her in German, "Well done!"
Source: Twitter

Trump Wants Nazi-Style Uniforms for Space Force

The White House has published its model for the ideal American soldier, and the model is the Nazi SS officer, the uniform of genocide.

Paul Verhoeven wrote in the Guardian in 2018 that he built his 1997 film Starship Troopers from Leni Riefenstahl’s footage so the Federation would read as Nazi propaganda, and that he put one character in an SS uniform to make the point unmistakable.

Audiences missed it, he said. He was wrong. Americans got it, backwards.

On Sunday Trump posted a “next generation” Space Force uniform whose own caption credits “the discipline and functionality of the Starship Trooper uniform,” and the official White House Rapid Response account reposted it.

Source: Orlando Sentinel

It is the Neil Patrick Harris intelligence officer coat of the Nazi SS, relabeled for “the Guardians of the space domain.”

Verhoeven filmed the villains as satire because he expected a lecture on fascism would be ignored. Americans watched his SS officer and ended up with a White House that costumed its soldiers to match, throwing Hitler salutes and licking Putin’s boots.

Source: Mitchell and Webb sketch in which Nazi officers realize they are the bad guys.