Live data from Hacker News

WADA Confirms Attack by Russian Cyber Espionage Group

wada-ama.org

41–50 of 89 posts

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#41

> Let it be known that these criminal acts are greatly compromising the effort by the global anti-doping community to re-establish trust in Russia Seems like they imply the Russian state is behind this but they don't explicitly say it, probably because they have no proof, as always. What trust do I have in WADA when they clearly have a bias against Russia?

The conclusion is not WADA's, so your distrust of WADA has very little to do with the story.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#42
post #22
post #16

Why the hell US government, US media and pro-US organizations (ex. WADA) says that the Russian government was behind all hacking attacks in the last 6 month (maybe year or even more)? It sounds like a broken joke from 60s... Yes, I'm Russian. Yes, I live in Russia. And Yes, I like my country.

> Why the hell US government, US media and pro-US organizations (ex. WADA) says that the Russian government was behind all hacking attacks in the last 6 month (maybe year or even more)? It sounds like a broken joke from 60s... You are likely on solid ground accusing the US government of using Russia as an excuse. When you accuse WADA of being "pro-US"; however, you lose all your credibility.

Probably you should read a data, leaked from WADA about US sportsmen and the drugs they used before talking about my credibility.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#43
post #27

Sadly, I conclude that devices connected to the Internet are irremediably insecure. Air-gap it or lose it, I guess.

In this case there wasn't even a real security vulnerability, just a spear-phishing attack. Organizations need to hold employees accountable for their own stupidity if they want to prevent this from happening. Any sane organization would fire an employee who gave a stranger keys to the office; falling for a phishing scam is the online equivalent of that.

> Any sane organization would fire an employee who gave a stranger keys to the office; falling for a phishing scam is the online equivalent of that.

No, they likely wouldn't fire someone unless they specifically had controls in place for that (eg. security clearance area). People "tailgate" at companies all the time.

http://www.pacifict.com/Story/

In addition, the "value" of these records shot up dramatically once Russia was banned. The security was not stepped up to match.

The real problem is the fact that managers DO request passwords, access control changes, etc. via email, and they do it more often than people get phished. So, people learn to give out information rather than protect it.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#44
post #41

> Let it be known that these criminal acts are greatly compromising the effort by the global anti-doping community to re-establish trust in Russia Seems like they imply the Russian state is behind this but they don't explicitly say it, probably because they have no proof, as always. What trust do I have in WADA when they clearly have a bias against Russia?

The conclusion is not WADA's, so your distrust of WADA has very little to do with the story.

What do you mean? That statement was made by Olivier Niggli, Director General, WADA

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#45
post #27

Sadly, I conclude that devices connected to the Internet are irremediably insecure. Air-gap it or lose it, I guess.

In this case there wasn't even a real security vulnerability, just a spear-phishing attack. Organizations need to hold employees accountable for their own stupidity if they want to prevent this from happening. Any sane organization would fire an employee who gave a stranger keys to the office; falling for a phishing scam is the online equivalent of that.

The security vulnerability is very real. Should this same treatment be applied to the people who write code? If a software vulnerability allows an attacker into the business should that developer be fired? What if it's a UI bug that causes the company to lose sales. Should they be on the hook?

I think a more constructive reaction would be to say that phishing training is important and should be implemented or revised. In addition technical solutions should be investigated. Perhaps some of the infallible people who never fall for phishing attacks can automate part of their brilliance for the mere mortals.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#46
post #41

Earlier quoted context omitted.

The conclusion is not WADA's, so your distrust of WADA has very little to do with the story.

What do you mean? That statement was made by Olivier Niggli, Director General, WADA

They are not the organization that conducted the investigation.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#47
post #16

Why the hell US government, US media and pro-US organizations (ex. WADA) says that the Russian government was behind all hacking attacks in the last 6 month (maybe year or even more)? It sounds like a broken joke from 60s... Yes, I'm Russian. Yes, I live in Russia. And Yes, I like my country.

Here's a description of Russian state sponsored trolling. It's worth a read, even though it's long.

http://www.stratcomcoe.org/internet-trolling-hybrid-warfare-...

Especially page 60 onwards is useful.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#48

> Let it be known that these criminal acts are greatly compromising the effort by the global anti-doping community to re-establish trust in Russia Seems like they imply the Russian state is behind this but they don't explicitly say it, probably because they have no proof, as always. What trust do I have in WADA when they clearly have a bias against Russia?

Usually I trust Kaspersky to ID the correct Advanced Persistent Threat when it's Western and FireEye when it's non-Western, in this case APT28 a.k.a Fancy Bear.

APT28 is pretty obviously Russia, due to character encodings in the files, timestamps, etc. etc. etc. If I'm not mistaken, the attacks almost always also leak the location of a particular Russian government building. The technical evidence for their previous attacks is so extensive it seems they want to be caught.

They're who the Russian government sends when they want to make it obvious it was them to other governments, but don't want to start an open conflict.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#49
post #28

While it is an evolving situation, at present, we believe that access to ADAMS was obtained through spear phishing of email accounts; whereby, ADAMS passwords were obtained enabling access to ADAMS account information confined to the Rio 2016 Games. It's amazing that people are still being phished successfully.

Maintaining the attitude that you are not susceptible to being phished is a great way to get phished.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#50
post #39
post #26

Earlier quoted context omitted.

What government and who are the "consultants" ?

There is an industry of reputable, large scale businesses that do attribution work. Generally, if you see attack attributions written up in major news outlets, one or more of them have concurred on the attribution. For instance: the HRC/DNC attribution started with CrowdStrike (whose executive team is not exactly HRC-friendly), and concurrences were later released by some of CrowdStrike's competitors. Attribution is…

So, what are the most common methods for this?
Post reply on HN