Live data from Hacker News

Notifying Our Users of Attacks by Suspected State-Sponsored Actors

yahoo-security.tumblr.com

1–10 of 46 posts

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#3
post #2

How do Yahoo, Google, Facebook, or others distinguish between state-sponsored actors and non-state-sponsored actors?

Also, what kinds of attacks are they trying to catch here? The bullet points in the article seem like phishing scams. Phone verification doesn't seem like it would do much since a sophisticated adversary has probably also compromised the phone network as well.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#7
post #2

How do Yahoo, Google, Facebook, or others distinguish between state-sponsored actors and non-state-sponsored actors?

I would assume sophistication, intensity, and the fact that as long as it's not the NSA doing it they'll get tipped off that China, Russia, Insert-Evil-Country-Here is running a campaign against them.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#8
post #5
post #4

Just what middle-America needs, notification that the russkies are coming for their baby pictures.

It's more likely to be the NSA nowadays. It would be good if these notifications said where the attacks appeared to originate.

Why would the NSA need to attack? They can just ask Yahoo for the data.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#9
post #3
post #2

How do Yahoo, Google, Facebook, or others distinguish between state-sponsored actors and non-state-sponsored actors?

Also, what kinds of attacks are they trying to catch here? The bullet points in the article seem like phishing scams. Phone verification doesn't seem like it would do much since a sophisticated adversary has probably also compromised the phone network as well.

By far the most common vector of state sponsored attacks is simple malicious email. Why waste your time and money when something simple works so well?

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#10
post #5
post #4

Just what middle-America needs, notification that the russkies are coming for their baby pictures.

It's more likely to be the NSA nowadays. It would be good if these notifications said where the attacks appeared to originate.

For US people in most industries, by volume, the Russians or Chinese are the most likely to compromise them. I suspect the NSA has a higher success rate, but with their pervasive surveillance and ability to legally compelling action, they're not the ones trying to bust into your email account all the time.
Post reply on HN