Got hacqued.
While in Singapore I was able to get ahold of some policeman who made some calls and was told it was waiting for me at the Lost and Found inside the Nice airport gift shop. I thanked him and made 24 hour layover in Nice.
Well, getting to the airport, I came tk this shop. I asked about the “sac a dos gris” in the other room. They checked their ordinateur: “NO, je suis desolee”. Sorry sir! I said you definitely have it, can you please go to that other room and check? “No sorry we cannot. It is not here. After a week we give things to the municipal lost and found. At the polics station. Go there.”
The day was ending (French govt services work til 4pm) so I raced to the municipal police station in Nice. I arrive and they have a bunch of keys and other things people lost around the city. I barely speak French but luckily a middle-aged lady was there who spoke good English. She helped me ask them. “No. Sorry. It is not here.” Are they sure? “Yes, we checked. Not here.”
She gave me a ride on her vespa (she had a motorcycle) and I treated her to dinner while we discussed the situation. We agreed I should go to the central police station after that and file a missing item report. Which I did (spoiler alert: doesn’t do anything, but standing in line is lesss than in US cities).
In the morning I went to the tram lost and found, before my flight. I had one hour. They didn’t have it either!
I flew home, dejected. My backups hadn’t been perfect; I had a lot of stuff on that computer, including an iOS App on XCode that I had to release to a lot of people! (And a couple Metamask wallets.)
Anyway I kept in touch with the nice policeman throughout. He went to the airport lost and found - the same one which refused to check the other room because their computer said it wasn’t there — and CONFIRMED that my bag was there.
But I wasn’t in Nice anymore. I filled out a “troov.com” report and explained where it was. They had found it! Paid for DHL. Saw it go to the central station in DHL and then sent back. Because it was missing a customs form for USA. I had filled out that form, but something had been wrong. Lost about $100…
Then, the lady offered to come pick it up for me. She came, and was thankfully given this bag. She mailed it with FedEx, and I received it. I covered the cost. We are still friends to this day, and when my dad goes to France, I am putting them in touch.
One moral from this story is: French employees love to say “No” to anything and everything. If their computer says the thing isn’t there, they won’t budge even when it’s the easiest thing to just check the other room manually.
Weak.
It's probably the quickest way to punish those people, just regular data leaks from the tax bureau.
I'm probably too optimistic, since this data is probably not admissible in court.
For government services, they are getting more and more common, it's scary.
Most media outlets will use "pirate informatique" (or just "pirate") when talking about hackers, and "piratage" for hacking. Example: [2]
[0] https://en.wikipedia.org/wiki/Office_qu%C3%A9b%C3%A9cois_de_...
[1] https://vitrinelinguistique.oqlf.gouv.qc.ca/resultats-de-rec...
[2] https://www.lapresse.ca/actualites/justice-et-faits-divers/2...
zakxxi•49m ago
* French tax authority (DGFiP) breach › ~678,000 records leaked, names, tax bracket, reference income, withholding rate
* Detection gap › intrusion spotted and cut off in late June, but the actual data theft wasn't discovered until the stolen data went up for sale on Aug 12, over a month later
* Second breach, same attacker › land registry (cadastre) systems, late July, claimed 2M+ people affected, alleged MFA bypass
* Third incident › French Ministry of Education systems also compromised in late July (staff data since 2001), disclosed quietly with little press coverage
* Legal precedent cited › a 2023 EU Court of Justice ruling (stemming from Bulgaria's 2019 tax agency breach) established that fear of misuse alone counts as damage, and shifts the burden of proof onto the agency to show its security was adequate
* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model
* Systemic issue › France's NIS2 transposition law has been stalled in parliament since 2024, partly over a dispute involving encryption backdoor provisions
* Broader angle › piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025–2026
INTPenis•35m ago
How many workplaces have I seen like this? A tale as old as IT.
eloisant•26m ago
And kids are back to school in one week.