Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

11–20 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#11

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

[deleted]

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#13
>> Earlier today, Citrix chief information security officer Stan Black gave his company's side of the story. He said that, as of right now, Citrix does not know exactly which documents the hackers obtained nor how they got in...

Ouch. The winner of "The worst position to be in today".

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#14
Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad.

It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of cryptographic keypair logins - we have already found the "2FA" in practice like emails and cellphone text messages not an adequate replacement. I'm aware there are other problems with storing your keys and loss but I believe that is a better approach for anything that needs security. I wish I could get my bank accounts to use key based logins.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#15
post #8

“Threat actors”. What’s wrong with the word “perpetrator” or simply “criminal”?

“Threat actor” is super vague but more specific than the words you proposed. https://en.m.wikipedia.org/wiki/Threat_actor I agree the jargon isn’t great, I’ve seen “attacker” and “malicious user” used in pentest reports and neither of those seems quite right either.

Also, they aren’t technically criminals if the attackers are state-sponsored and conducting an act of war. “Threat-actor” seems exactly like the type of legalese a government relies on when crafting the story around its own retaliation or justification for future aggression. I think it’s just entered the lexicon when talking about these types of incidents.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#16

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

I don't have a LinkedIn page, or any other social media for this matter. Does that make me a non-trusrworthy person now? This is horrible. (I don't disagree with your other points).

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#17
post #15
post #8

Earlier quoted context omitted.

“Threat actor” is super vague but more specific than the words you proposed. https://en.m.wikipedia.org/wiki/Threat_actor I agree the jargon isn’t great, I’ve seen “attacker” and “malicious user” used in pentest reports and neither of those seems quite right either.

Also, they aren’t technically criminals if the attackers are state-sponsored and conducting an act of war. “Threat-actor” seems exactly like the type of legalese a government relies on when crafting the story around its own retaliation or justification for future aggression. I think it’s just entered the lexicon when talking about these types of incidents.

I agree, there are no criminals at the nation-state level, only other actors.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#18

Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad. It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of c…

Totally agree. My guess — and it’s obviously nothing more than that — is that they don’t fully know yet, but it might seem better and easier to solve than the alternative that there’s very little organizations in this position can ever actually do to prevent sophisticated attacks.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#19
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

Now extend that to voting systems too... not just folly, but criminal insanity.

I work with digitisation in the public sector of Denmark. We’ve digitised our elections, but we’ve digitised the part that makes sense, the registration you do before you’re handed you ballot.

In the old days, we used to have big books where you’d get crossed off after you were identified. This naturally takes a lot of time, so today we print a little bar code on the piece of paper that we mail every adult citizen at every election. This means that we can scan you instead of manually crossing you off in a book.

We still have queues at prime time, but they are 10-15 minutes instead of two hours.

The actual voting is done with paper, so that there is a paper trail.

This is the only thing that makes sense. Especially when you look at the business side of things. We reduce the hassle for citizens (our customers of sorts) and we maintain security. Sure we could provide results faster if we counted votes digitally, and you could frankly also provide a paper trail if the machine printed you vote, but does speed of counting really matter? Financially digital vote counting would be insanely more expensive, because public IT systems are insanely expensive and paying staff a little extra to count votes isn’t.

I mean, the registration system is really expensive as well, but at least it benefits the citizens, so that is a reasonable sacrifice to us. But digital voting? That’s as you put it, insane.

It’s not a democratic process if you don’t have the physical votes and a system which makes sure they aren’t tampered with.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#20
post #5

haveibeenpwned could/should make a browser extension that tell you if the site your on has been pwned

HIBP isn't about pwned sites. It's about leaked credentials. The source of leaked data on HIBP isn't verifiable in most cases.
Post reply on HN