Live data from Hacker News

WADA Confirms Attack by Russian Cyber Espionage Group

wada-ama.org

31–40 of 89 posts

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#32
post #16

Why the hell US government, US media and pro-US organizations (ex. WADA) says that the Russian government was behind all hacking attacks in the last 6 month (maybe year or even more)? It sounds like a broken joke from 60s... Yes, I'm Russian. Yes, I live in Russia. And Yes, I like my country.

Because it serves their interest to say so, regardless if it's actually true. Russia is a welcome target and it's basically impossible to prove who's reponsible for a hack like this (the korean symbols in the Fancy Bear's website's [1] source code are cute though).

Also, that's how media works these days. One press release to Reuters, and all the newspapers publish the same "facts".

That being said, I think it's fairly plausible that some actor with relations to Russia would publish documents like these.

[1] http://fancybear.net

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#33
post #28

While it is an evolving situation, at present, we believe that access to ADAMS was obtained through spear phishing of email accounts; whereby, ADAMS passwords were obtained enabling access to ADAMS account information confined to the Rio 2016 Games. It's amazing that people are still being phished successfully.

Why? It's the standard security imbalance. The attacker only has to be successful once while the defenders have to never make a mistake.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#34
post #28

While it is an evolving situation, at present, we believe that access to ADAMS was obtained through spear phishing of email accounts; whereby, ADAMS passwords were obtained enabling access to ADAMS account information confined to the Rio 2016 Games. It's amazing that people are still being phished successfully.

I disagree. The attacks are becoming more sophisticated and fool the most seasoned techies. Additionally, when I ask "Baby boomers" if they understand phishing, they oftentimes say yes but then have trouble explaining what it is or how it is executed.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#35
post #28

While it is an evolving situation, at present, we believe that access to ADAMS was obtained through spear phishing of email accounts; whereby, ADAMS passwords were obtained enabling access to ADAMS account information confined to the Rio 2016 Games. It's amazing that people are still being phished successfully.

Spear phishing is not your regular fishing. It is tailored to your expectations and preferences. If you really expect some important email, you can easily click the link without looking at it.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#36
post #13

Sadly, I conclude that devices connected to the Internet are irremediably insecure. Air-gap it or lose it, I guess.

That is ultimately too pessimistic. Security is a gradient, and there's a lot you can do make yourself both a smaller target, and a harder target. Compartmentalization is one of the strongest defense tools we have. For example, with the icloud leaks an attacker was able to gain access to all the data in a single strike. If it's true that Apple can no longer decrypt user's icloud data, an attacker now needs to hack pe…

> hacking will become harder, the rewards will plummet, and the world will be safer...

...security will become less of a concern, hacking will become easier, the rewards will rise, security will be taken more seriously...

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#37
post #27

Sadly, I conclude that devices connected to the Internet are irremediably insecure. Air-gap it or lose it, I guess.

In this case there wasn't even a real security vulnerability, just a spear-phishing attack. Organizations need to hold employees accountable for their own stupidity if they want to prevent this from happening. Any sane organization would fire an employee who gave a stranger keys to the office; falling for a phishing scam is the online equivalent of that.

[deleted]

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#38
> “This is just the tip of the iceberg,” a statement posted to the Fancy Bears site said. “Today’s sport is truly contaminated while the world is unaware of the large number of American doping athletes.”

What's up with hackers and their English grammar? Shouldn't it be doping American athletes? This reminds of the adjective-word-order rule and Tolkien's "green great dragons" story. [1]

[1] http://languagelog.ldc.upenn.edu/nll/?p=27890

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#39
post #26
post #25

Earlier quoted context omitted.

Government & consultants.

What government and who are the "consultants" ?

There is an industry of reputable, large scale businesses that do attribution work. Generally, if you see attack attributions written up in major news outlets, one or more of them have concurred on the attribution.

For instance: the HRC/DNC attribution started with CrowdStrike (whose executive team is not exactly HRC-friendly), and concurrences were later released by some of CrowdStrike's competitors.

Attribution is obviously deeply imperfect. But it's not as simple as "this sure seems like Russian and there's some Cyrillic so let's call it a day".

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#40
> Let it be known that these criminal acts are greatly compromising the effort by the global anti-doping community to re-establish trust in Russia

Seems like they imply the Russian state is behind this but they don't explicitly say it, probably because they have no proof, as always. What trust do I have in WADA when they clearly have a bias against Russia?

Post reply on HN