Live data from Hacker News

Notifying Our Users of Attacks by Suspected State-Sponsored Actors

yahoo-security.tumblr.com

11–20 of 46 posts

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#12
"State-sponsored actors" sounds like over-specification. If Yahoo detects a "sophisticated attack" from a lone jerk with a computer, do they not notify affected users of defensive actions to take?

It's no doubt interesting to know that your account is being targeted by your own or some other government, but identification seems secondary to detection and response.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#13
post #2

How do Yahoo, Google, Facebook, or others distinguish between state-sponsored actors and non-state-sponsored actors?

I want one of these companies to define state-sponsored actors?

It's great if one is a dissenter in Egypt and the authorities there go after their Yahoo! account but what about a US citizen's account being attacked by the FBI or NSA?

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#14
post #2

How do Yahoo, Google, Facebook, or others distinguish between state-sponsored actors and non-state-sponsored actors?

https://en.wikipedia.org/wiki/Cybersecurity_Information_Shar...

This passed along with the budget bill at the end of last week. It establishes a system whereby the US defense department shares with corporations their signals for detecting state-sponsored attacks, and companies are allowed to opt in to sharing anonymized attack information with the DoD

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#15
Google has a state sponsored actors warning. I received it a few years ago, a red bar across the top of GMail.

So I turned on two factor auth and the warnings stopped.

I wish I knew which state and why my account was being attacked? I'm guessing it was not a specific attack but perhaps the attacker was trying credentials found in some other breach.

Considering that Google cooperates with the USG, I'd guess that it was some state other than the US, but who knows. I'm not aware of having done anything that would be of concern to any government.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#16
post #2

How do Yahoo, Google, Facebook, or others distinguish between state-sponsored actors and non-state-sponsored actors?

https://en.wikipedia.org/wiki/Cybersecurity_Information_Shar... This passed along with the budget bill at the end of last week. It establishes a system whereby the US defense department shares with corporations their signals for detecting state-sponsored attacks, and companies are allowed to opt in to sharing anonymized attack information with the DoD

CISA is a terrible bill and not a solution to this problem. Security teams have been able to manage this data on their own for years without government intervention.

There have always been other methods for determining if an attacker is state sponsored. One example: Seeing your account, and a number of dissident or activists being attacked from a block of IPs or similar password attempts, probably means the attack is state sponsored.

That being said, in security, attribution is a very hard problem, and the methods used to determine state sponsored attacks are also quite hard to design.

There's a reason why companies won't elaborate on how they do this, but it is usually a combination of login/account intelligence and threat feeds.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#18
post #16

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Cybersecurity_Information_Shar... This passed along with the budget bill at the end of last week. It establishes a system whereby the US defense department shares with corporations their signals for detecting state-sponsored attacks, and companies are allowed to opt in to sharing anonymized attack information with the DoD

CISA is a terrible bill and not a solution to this problem. Security teams have been able to manage this data on their own for years without government intervention. There have always been other methods for determining if an attacker is state sponsored. One example: Seeing your account, and a number of dissident or activists being attacked from a block of IPs or similar password attempts, probably means the attack is…

>> Seeing your account, and a number of dissident or activists being attacked from a block of IPs or similar password attempts, probably means the attack is state sponsored.

Used to work at a fairly large global corporation. One day I was chatting up one of the senior sys admins. He was talking about the incredible traffic that bombards their server everyday. I was pretty naive back then and said, "Cmon man, it can't be that much!"

He opened his terminal and ran a simple monitoring tool, then opened one another terminal. In one was the constant traffic to several of their applications that were from a specific block of IP addresses he thought he had traced back to China. The other window was a running queue of mistyped password attempts. It was like clockwork. They'd try three, get kicked out of the system, then in an instant, you'd see a flurry of new IP addresses from the same block, then some more attempts to guess the password. Kicked out, rinse, repeat.

In the span of five minutes, I must have seen two dozen failed attempts to try and do a dictionary password attack on their login page. He guessed it was some kind of a bot that was running the tests considering how mechanical and orderly the attacks were.

It really opened my eyes as to how often and how many businesses these governments go after for intellectual property.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#19
post #2

How do Yahoo, Google, Facebook, or others distinguish between state-sponsored actors and non-state-sponsored actors?

https://en.wikipedia.org/wiki/Cybersecurity_Information_Shar... This passed along with the budget bill at the end of last week. It establishes a system whereby the US defense department shares with corporations their signals for detecting state-sponsored attacks, and companies are allowed to opt in to sharing anonymized attack information with the DoD

I have long suspected that the overwhelming majority of any "sharing" that takes place will be one-sided, from corporations to government.

In previous jobs, I've been involved with various ISACs and while there was some sharing of information from the government, it was often "watered down", vague, and mostly unactionable.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#20
post #5

Earlier quoted context omitted.

It's more likely to be the NSA nowadays. It would be good if these notifications said where the attacks appeared to originate.

Why would the NSA need to attack? They can just ask Yahoo for the data.

Yep, or just intercept it themselves as it crosses the wire.
Post reply on HN