ChrisArchitect
2 hours ago
Previously (in english): https://news.ycombinator.com/item?id=49298303
2 hours ago
Previously (in english): https://news.ycombinator.com/item?id=49298303
3 hours ago
The post is verbose, but lacks substance:
- The last two sections (≈20% of the article, 5.Cloud and 6.IA) are barely relevant.
- Some comparisons are questionable. It claims that, since some taxes data was compromised, the trust in the national Federated Identity is eroded "as if Facebook Connect was hacked". That's strange, I think it should be "as the trust in Facebook Connect would be eroded when Facebook is hacked". Anyway, I think most people won't care.
- Some sentences make no sense: "Le piratage de Ficoba semble en être l'exemple type"... But "Ficoba" is not mentioned anywhere, and, though I know what the word means, I can't guess what the sentence points to.
The OP should have mentioned another important hack of French national structures that happened in december 2025 and which is well documented. IIRC, through phishing, a keylogger was installed on a teacher's computer. Then the hackers got credentials to an internal training platform for teachers. Then they exploited multiple security breaches and connections between Ministries to get access to the national police files.
3 hours ago
> t claims that, since some taxes data was compromised, the trust in the national Federated Identity is eroded "as if Facebook Connect was hacked". [... ] Anyway, I think most people won't care.
The taxes services is one of the oldest online government service in France that has existed, with a very wide usage.
As people had already that authentication as an identity provider, it was natural to reuse that authentication (not the password, but 3rd party auth à la OAuth, but a french government standard) to authenticate to government services that went online later.
So if the taxes auth is compromised (so far I haven't seen enough details about the coverage of the leak), that's a real concern.
3 hours ago
[flagged]
4 hours ago
After 3-4 decades of networked compute, is it now fair to say that 'there are two types of organizations in the world: those that have been hacked, and those that know that they have been hacked.'
4 hours ago
"got hacked (in French)".
Got hacqued.
4 hours ago
"hackée" would be the real anglicisme of hacked. Lot of english words are used like real french verb (-er termination) (hacker, booker, spoiler, manager, etc)
3 hours ago
I've never had such a linguistic double take after hearing a colleague, who grew up in France, tell me that Nike's or Adidas' billboards in France say: "Le leader en sportswear", pronounced as if it contained four French words (lee-dayr, spôrt-swear, stress on the final syllable in both cases).
2 hours ago
In Russian the word for train is poezd, and the prepositional form is poezdje, so you say "I am on the train" "ya v poezdje" (Russian has no articles and drops the copula when it carries no information, so word for word it's "I on train.") One of my friends once told her mom on the phone "ya v trenje" meaning that she took the word "train," pronounced it as though it were a native Russian word "tren", and added the typical masculine inanimate prepositional ending to it. Kinda funny.
3 hours ago
My favourite (heard in a bar in Paris): On y go ?
an hour ago
Bet ya un pain au chocolat you heard that in the Marais, where les peoples hang out :D
21 minutes ago
Actually on the Rue du Faubourg-Saint-Denis
3 hours ago
Actually they use the term 'piratage'
3 hours ago
yeah they even used it at the beginning of the article
3 hours ago
\s Take my angry upvote!
3 hours ago
'acked
3 hours ago
That could be cockney, though.
3 hours ago
Is it masculine or feminine?
4 hours ago
I lol'ed, but I imagine outside of Quebec the French probably just use the English word "hacking" when referring to a computer hack.
4 hours ago
In Quebec, the OQLF [0] recommends "bidouilleur" (which I've heard) and "fouineur" (which makes sense, but isn't really common) instead of hacker [1].
Most media outlets will use "pirate informatique" (or just "pirate") when talking about hackers, and "piratage" for hacking. Example: [2]
[0] https://en.wikipedia.org/wiki/Office_qu%C3%A9b%C3%A9cois_de_...
[1] https://vitrinelinguistique.oqlf.gouv.qc.ca/resultats-de-rec...
[2] https://www.lapresse.ca/actualites/justice-et-faits-divers/2...
4 hours ago
French would use "piratage [informatique]" (roughly "digital piracy"). However, "hacker" is used to name the person committing the crime.
2 hours ago
I would think the person committing piratage would be called a pirate.
2 hours ago
Un pirate commits la piraterie
4 hours ago
ordinateur-ed
4 hours ago
I once accidentally left my backpack in Nice’s tram, containing mon ordinateur principal. I was flying to Balaji’s Network State conference in Singapore and had no time to go back. I did get ahold of a tram operator and another tram operator had found it at the end of the line. I had left my whatsapp number for her and had to run.
While in Singapore I was able to get ahold of some policeman who made some calls and was told it was waiting for me at the Lost and Found inside the Nice airport gift shop. I thanked him and made 24 hour layover in Nice.
Well, getting to the airport, I came tk this shop. I asked about the “sac a dos gris” in the other room. They checked their ordinateur: “NO, je suis desolee”. Sorry sir! I said you definitely have it, can you please go to that other room and check? “No sorry we cannot. It is not here. After a week we give things to the municipal lost and found. At the polics station. Go there.”
The day was ending (French govt services work til 4pm) so I raced to the municipal police station in Nice. I arrive and they have a bunch of keys and other things people lost around the city. I barely speak French but luckily a middle-aged lady was there who spoke good English. She helped me ask them. “No. Sorry. It is not here.” Are they sure? “Yes, we checked. Not here.”
She gave me a ride on her vespa (she had a motorcycle) and I treated her to dinner while we discussed the situation. We agreed I should go to the central police station after that and file a missing item report. Which I did (spoiler alert: doesn’t do anything, but standing in line is less than in US cities).
That night I chose to stay at some rinkydink place in Nice, because why not (I was by myself) and got up around 4am to take the bus to the tram network’s lost and found — the last place it could be. I would have aittle time before my flight.
In the morning I got up early and got to that Lost and Found, before my flight. I had one hour. It was located near a university, and after wandering around I had found the little enclave. The staff there were very nice — but they didn’t have it either!
I flew home, dejected. My backups hadn’t been perfect; I had a lot of stuff on that computer, including an iOS App on XCode that I had to release to a lot of people! (And a couple Metamask wallets.)
Anyway I kept in touch with the nice policeman throughout. He went to the airport lost and found - the same one which refused to check the other room because their computer said it wasn’t there — and CONFIRMED that my bag was there. They had let him check the back room, you see!
But I wasn’t in Nice anymore. I filled out a “troov.com” report and explained where it was. They had found it! Paid for FedEx. Over the next few days thanks to the Tracking I saw it go to the central station in France and then sent back. Because it was missing a customs form for USA. I had filled out that form, but something had been wrong. I had spoken to the main FedEx customs-facing team in Memphis for a few days, and they thought it was in USA already. They were wrong. Their system was also blind to this. Anyway, I saw it go back to that airport lost and found, a week later. Lost about $100…
Then, the lady offered to come pick it up for me. She came, and was thankfully given this bag. She mailed it with DHL, and I received it. It was really overjoyed when it finally arrived, a month and a half after I had lost it! I of course sent the lady a payment to cover the cost. She did not want any other compensation. We are still friends to this day, and when my dad goes to France, I am putting them in touch.
One moral from this story is: French employees love to say “No” to anything and everything. If their computer says the thing isn’t there, they won’t budge even when it’s the easiest thing to just check the other room manually. Unless you are a local policeman!
The other moral - back up your stuff! Have SyncThing or your own machine in the cloud. Especially if you travel to conferences, like me.
3 hours ago
> French employees love to say “No” to anything and everything.
Obviously an overgeneralization.
In general employees in lost and found offices are quite low on the social scale, but still in a position of power regarding people coming to the office. I guess that this behaviour is not so french. In some other countries where corruption is common in public services in relation to low wages, worse things may happen at lost and found.
2 hours ago
That's not how Jason Bourne handled paperwork.
3 hours ago
This is a real issue btw, I think it's globalized but we have it a lot in France. People love abusing any power they have on you, they love telling you no and that you're wrong and they know better.
The other issue is that public service employees tend to be huge slackers, and when you have the misfortune of ending up in a situation that requires multiple people working together, you'll be probably there for a few weeks because they can't go further than their own desk.
When I was coming back from Canada, I had to remake my social security card since it was transferred to Canada (through an official transfer that made me eligible to the Canadian social security). But in France, no one knew how that worked, and I basically spent two months calling them weekly for updates (with various people telling me contradictory things) before someone finally went ahead and made sure all the necessities were taken care of.
I frankly hate dealing with French public services and avoid it like the plague.
3 hours ago
> public service employees tend to be huge slackers
Why is that so? I’ve seen it in literally every single country I’ve had to deal with the authorities across Europe, Asia, and the Americas.
Even in countries we like to call progressive (eg Finland, Estonia) the public service workers are so much slower than their compatriots in the private sector. (Even though they are still much faster than the lethargic dinosaurs you meet in Germany)
2 hours ago
Lack of competition, governments get money (almost) regardless of how shit they are. It really kills incentive when the money shows up no matter what.
When a project falls through in the private sector, it can be existential for the workers or at least make their lives difficult in the future (anyone who has worked for a cash constrained business knows it just generally sucks).
When a "project" falls through in the government, oh well, see ya tomorrow.
4 hours ago
faire l'haque
an hour ago
I wrote this article and I found the comments funny. I have an updated version in English here : https://www.linkedin.com/posts/tariqkrim_french-tax-authorit...
3 hours ago
"Ce scénario n'est pas théorique, il a déjà eu lieu. En octobre 2025, la Fédération française de tir se fait voler les données de près d'un million de licenciés et d'anciens licenciés : état civil, adresse postale, téléphone, numéro de licence.
Les mois suivants, des individus se présentent au domicile de licenciés en se faisant passer pour des policiers ou des gendarmes, parfois en tenue, pour se faire remettre des armes. Des vols sont constatés à Nice, à Paris, à Limoges, à Décines."
Sounds like a far fetched movie!
an hour ago
Wow, indeed rare that hacks result in real-life visits, and here even specifically to pretend-confiscate weapons. That's a well-plannee (or excellently opportunist) coup.
4 hours ago
Website dedicated to public and private data breaches in France : frenchbreaches.com/
For government services, they are getting more and more common, it's scary.
4 hours ago
Meanwhile in Norway much of this wouldn't matter because the accessed information would have been public anyway. The non-tax PII is still a loss of course.
3 hours ago
I'm surprised. The stolen data had two parts: some relevant to the income taxes paid, some detailing the real estate (houses and lands) owned by the household. Are both of them public in Norway?
Anyway, the main problem is that the breaches into the many French national data stores seem increasingly frequent.
4 hours ago
We have a certain degree of financial privacy rights in the rest of the world.
3 hours ago
What's the purpose of privacy when it comes to taxes and real estate?
3 hours ago
Protecting oligarchy, mostly.
Those same countries that treat financial privacy as axiomatic are trying their best to undermine chat encryption and would throw ed Snowden in prison given half a chance.
4 hours ago
I've lived for 10 years in France and virtually all spam I receive is from French leaks (I know due to dedicated addresses), which have kept happening since I left. Bourse des Vols, Free, even Doctolib and my hospital (!), and now this. I simply can't trust French companies, it's an awful anecdotal experience.
4 hours ago
A couple of days ago I received a strange letter from the France tax agency. For context: I received it in my home in Italy, and it was addressed to someone else (perhaps a previous tenant of the house?). It seemed legit but completely misdirected. Or perhaps it was generated from the data in this hack.
4 hours ago
I want to believe this will reveal people who do tax fraud or potentially illegal tax dodging schemes
It's probably the quickest way to punish those people, just regular data leaks from the tax bureau.
I'm probably too optimistic, since this data is probably not admissible in court.
an hour ago
A similar hack created The Panama Papers. Not much came from those either. Like the Epstein Files, it may make for interesting reading, but I don't expect much legal action.
an hour ago
I believe that we established all those government systems are fairly easy to hack. I remember some French military naval construction network got owned about a year ago, much worst in a sense.
My guess is since a global conflict is ramping up this is only the beginning and we are about to see some real damage.
It is fairly easy to create chaos in a country for a few weeks if you start disrupting the grid, payments or internet access.
2 hours ago
i think we are on the verge of some serious event that will affect the whole ai industry.
4 hours ago
They couldn't even wipe out everybody's tax bill.
Weak.
2 hours ago
I mean, which official service has not been hacked now ?
4 hours ago
Posted this because it's a solid post-mortem on the recent French tax agency breach, going beyond the headlines into the detection gap, the legal angle, and the broader systemic issues. Quick summary of the key points below (original is in French):
* French tax authority (DGFiP) breach › ~678,000 records leaked, names, tax bracket, reference income, withholding rate
* Detection gap › intrusion spotted and cut off in late June, but the actual data theft wasn't discovered until the stolen data went up for sale on Aug 12, over a month later
* Second breach, same attacker › land registry (cadastre) systems, late July, claimed 2M+ people affected, alleged MFA bypass
* Third incident › French Ministry of Education systems also compromised in late July (staff data since 2001), disclosed quietly with little press coverage
* Legal precedent cited › a 2023 EU Court of Justice ruling (stemming from Bulgaria's 2019 tax agency breach) established that fear of misuse alone counts as damage, and shifts the burden of proof onto the agency to show its security was adequate
* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model
* Systemic issue › France's NIS2 transposition law has been stalled in parliament since 2024, partly over a dispute involving encryption backdoor provisions
* Broader angle › piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025–2026
4 hours ago
* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model
How many workplaces have I seen like this? A tale as old as IT.
3 hours ago
> Broader angle › piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025–2026
I was wondering how they would find a way to blame the United States.
3 hours ago
Quintessentially French.
4 hours ago
It's a big mess in schools now, the whole messenging system is down as a preventive measure so the only way they can communicate (between each other, to parents, etc) is by phone.
And kids are back to school in one week.
4 hours ago
[dead]
2 hours ago
[flagged]