> Let it be known that these criminal acts are greatly compromising the effort by the global anti-doping community to re-establish trust in Russia Seems like they imply the Russian state is behind this but they don't explicitly say it, probably because they have no proof, as always. What trust do I have in WADA when they clearly have a bias against Russia?
WADA Confirms Attack by Russian Cyber Espionage Group
41–50 of 89 posts
Re: WADA Confirms Attack by Russian Cyber Espionage Group
#42Why the hell US government, US media and pro-US organizations (ex. WADA) says that the Russian government was behind all hacking attacks in the last 6 month (maybe year or even more)? It sounds like a broken joke from 60s... Yes, I'm Russian. Yes, I live in Russia. And Yes, I like my country.
> Why the hell US government, US media and pro-US organizations (ex. WADA) says that the Russian government was behind all hacking attacks in the last 6 month (maybe year or even more)? It sounds like a broken joke from 60s... You are likely on solid ground accusing the US government of using Russia as an excuse. When you accuse WADA of being "pro-US"; however, you lose all your credibility.
Re: WADA Confirms Attack by Russian Cyber Espionage Group
#43Sadly, I conclude that devices connected to the Internet are irremediably insecure. Air-gap it or lose it, I guess.
In this case there wasn't even a real security vulnerability, just a spear-phishing attack. Organizations need to hold employees accountable for their own stupidity if they want to prevent this from happening. Any sane organization would fire an employee who gave a stranger keys to the office; falling for a phishing scam is the online equivalent of that.
No, they likely wouldn't fire someone unless they specifically had controls in place for that (eg. security clearance area). People "tailgate" at companies all the time.
http://www.pacifict.com/Story/
In addition, the "value" of these records shot up dramatically once Russia was banned. The security was not stepped up to match.
The real problem is the fact that managers DO request passwords, access control changes, etc. via email, and they do it more often than people get phished. So, people learn to give out information rather than protect it.
Re: WADA Confirms Attack by Russian Cyber Espionage Group
#44> Let it be known that these criminal acts are greatly compromising the effort by the global anti-doping community to re-establish trust in Russia Seems like they imply the Russian state is behind this but they don't explicitly say it, probably because they have no proof, as always. What trust do I have in WADA when they clearly have a bias against Russia?
The conclusion is not WADA's, so your distrust of WADA has very little to do with the story.
Re: WADA Confirms Attack by Russian Cyber Espionage Group
#45Sadly, I conclude that devices connected to the Internet are irremediably insecure. Air-gap it or lose it, I guess.
In this case there wasn't even a real security vulnerability, just a spear-phishing attack. Organizations need to hold employees accountable for their own stupidity if they want to prevent this from happening. Any sane organization would fire an employee who gave a stranger keys to the office; falling for a phishing scam is the online equivalent of that.
I think a more constructive reaction would be to say that phishing training is important and should be implemented or revised. In addition technical solutions should be investigated. Perhaps some of the infallible people who never fall for phishing attacks can automate part of their brilliance for the mere mortals.
Re: WADA Confirms Attack by Russian Cyber Espionage Group
#46Re: WADA Confirms Attack by Russian Cyber Espionage Group
#47Why the hell US government, US media and pro-US organizations (ex. WADA) says that the Russian government was behind all hacking attacks in the last 6 month (maybe year or even more)? It sounds like a broken joke from 60s... Yes, I'm Russian. Yes, I live in Russia. And Yes, I like my country.
http://www.stratcomcoe.org/internet-trolling-hybrid-warfare-...
Especially page 60 onwards is useful.
Re: WADA Confirms Attack by Russian Cyber Espionage Group
#48> Let it be known that these criminal acts are greatly compromising the effort by the global anti-doping community to re-establish trust in Russia Seems like they imply the Russian state is behind this but they don't explicitly say it, probably because they have no proof, as always. What trust do I have in WADA when they clearly have a bias against Russia?
APT28 is pretty obviously Russia, due to character encodings in the files, timestamps, etc. etc. etc. If I'm not mistaken, the attacks almost always also leak the location of a particular Russian government building. The technical evidence for their previous attacks is so extensive it seems they want to be caught.
They're who the Russian government sends when they want to make it obvious it was them to other governments, but don't want to start an open conflict.
Re: WADA Confirms Attack by Russian Cyber Espionage Group
#49While it is an evolving situation, at present, we believe that access to ADAMS was obtained through spear phishing of email accounts; whereby, ADAMS passwords were obtained enabling access to ADAMS account information confined to the Rio 2016 Games. It's amazing that people are still being phished successfully.
Re: WADA Confirms Attack by Russian Cyber Espionage Group
#50Earlier quoted context omitted.
What government and who are the "consultants" ?
There is an industry of reputable, large scale businesses that do attribution work. Generally, if you see attack attributions written up in major news outlets, one or more of them have concurred on the attribution. For instance: the HRC/DNC attribution started with CrowdStrike (whose executive team is not exactly HRC-friendly), and concurrences were later released by some of CrowdStrike's competitors. Attribution is…