Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

1–10 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#3
Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable.

I wouldn't put personal data I am not willing to lose online or on an intranet at all anymore. No amount of money and engineering seems to be able to keep up, and companies prove over and over that they are negligent, naive, or simply a few steps too far behind.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#4
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

Now extend that to voting systems too... not just folly, but criminal insanity.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#6
The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company.

1 - their CEO has no real linkedIn history [1]

2 - they revenue and employment went off the chart just in 2 quarters [2]

3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at these evidence with some skepticism.

Am I being over-cynical here?

1 - https://www.linkedin.com/in/charles-yoo-365201165/

2 - https://www.zoominfo.com/c/resecurity-inc/353866377

edit - formating.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#7
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

For a while I've thought "patch holes as we discover them" is the wrong approach to computer security.

Perhaps we should be using formal proof systems? Perhaps we should just admit that computers are bad at holding secrets, and instead make everything on a computer public.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#8

“Threat actors”. What’s wrong with the word “perpetrator” or simply “criminal”?

“Threat actor” is super vague but more specific than the words you proposed.

https://en.m.wikipedia.org/wiki/Threat_actor

I agree the jargon isn’t great, I’ve seen “attacker” and “malicious user” used in pentest reports and neither of those seems quite right either.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#10

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Given an absence of even other vague data like 'exfiltrated data IP addresses were registered as Iranian' (not conclusive proof in itself given that the end devices could have been compromised) I'd say there is reason to be skeptical until they can provide more evidence.
Post reply on HN