Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

31–40 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#31

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

I've looked over their website and I'm confused about what they actually do. They are "trusted by leading Fortune 500 corporations" apparently (with logos for Microsoft and Amazon), but the entire "Interested in our solutions" section is a sign up form. What am I signing up for? It's unusual for a company to barely try to promote their products.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#32
post #16

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

I don't have a LinkedIn page, or any other social media for this matter. Does that make me a non-trusrworthy person now? This is horrible. (I don't disagree with your other points).

I also dont have a LinkedIn page, quite amusing that people find that a problem

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#33

Earlier quoted context omitted.

HIBP isn't about pwned sites. It's about leaked credentials. The source of leaked data on HIBP isn't verifiable in most cases.

Nope. https://haveibeenpwned.com/PwnedWebsites

OK, so there's a Yahoo! breach from 2012. Should I not visit Yahoo now?

Also please note the '?' marks for unverified sources.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#34
post #16

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

I don't have a LinkedIn page, or any other social media for this matter. Does that make me a non-trusrworthy person now? This is horrible. (I don't disagree with your other points).

TLDR; in some jobs, you can't have social media accounts.

I have some contact with cybersec in Europe and it is very common that cybersec professionals in gov and mil positions do not have any social media accounts under their own name, and certainly not linkedin. Social media makes you too much of a target and reveals too much about your org. When promoted to a public-facing position the person then suddenly "appears" from nowhere and the media profile has as little information as possible. Real professionals use those accounts only from designated computers, and if you are high ranking enough (head of...) in fact never use them at all, but rather have someone else using them for you. All in the name of keeping your own actions and locations away from the curious.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#35

Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad. It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of c…

Could be to avoid liability?

> Why were you hacked

> Weak passwords

> What are you going to do about it

> We've forced all systems and employees to regenerate passwords and service keys

Now lets try this again without an honest answer

> How were you hacked

> No idea

> What are you going to do? Are you still vulnerable?

> No idea. We'll have to do an extensive audit. No one knows how long this will take. There's not even an inventory of systems or data flow

> Could they have installed backdoors

> No idea

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#36

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Agreed that something seems off.

Generous interpretation - they're brand new (first Tweet 2/13/2019, first blog 2/19/2019).

Would love to know if those logos & awards are legit (quick search of the awards makes some look like pay to win).

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#37

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

It’s absolutely reasonable to be critical of any accusations that “Iran did it” or any other nation that the US considers enemies. Didn’t our security ministers claim North Korea was behind the Sony hacks when Obama was in office? We were never given any proof, so it’s impossible to verify... When you consider the way we lie on international affairs, all statements our government makes must be considered suspect. This is not unique to the US by the way, so treat your own state similarly.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#38
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

> I wouldn't put personal data I am not willing to lose online or on an intranet at all anymore

Anymore? Not trusting the internet used to be the default.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#39

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Good catch, that is called a 3 letter agency front.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#40

“Threat actors”. What’s wrong with the word “perpetrator” or simply “criminal”?

Because increasingly state actors are involved and it's not simple crime.

I don't think that's the reason; if someone who happens to be employed by a government commits a crime in their jurisdiction, they're still a perpetrator and a criminal.

"Threat actor" is actually more specific; it refers to someone behaving in a threatening manner without regard to their legal status or jurisdiction.

Post reply on HN