Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

41–50 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#41

Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad. It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of c…

Same tactic as what's used on Twitter accounts.

And same as I said previously: If the bad actors can brute force weak passwords, the company itself should be able to do it too and force those with weak passwords to update them.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#42

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

It’s absolutely reasonable to be critical of any accusations that “Iran did it” or any other nation that the US considers enemies. Didn’t our security ministers claim North Korea was behind the Sony hacks when Obama was in office? We were never given any proof, so it’s impossible to verify... When you consider the way we lie on international affairs, all statements our government makes must be considered suspect. Thi…

there is one small nuisance here - if we start to treat all governments equally skeptic, we should also "fry live" all large corporations too.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#43
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

My counter-point to this would be that we haven't seen significant breaches (at least, not on the scale of this) from the tech giants (FAANG and co). So there are companies that can keep your data safe. They're just vanishingly few.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#44

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Wtf is this "zoominfo" site that, upon clicking "Read More", tries to drive-by download an exe onto my computer? What is this, 2002?

Wow, I read the EULA-thing for that executable.

> I Agree to the Terms of Service and Privacy Policy I understand that I will receive a subscription to Zoominfo Community Edition at no charge in exchange for downloading and installing the ZoomInfo which, among other features involves sharing my business contacts as well as headers and signature blocks from emails that I receive.

It's effectively malware though at least they display it up-front, which is more than can be said for most.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#45
post #43
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

My counter-point to this would be that we haven't seen significant breaches (at least, not on the scale of this) from the tech giants (FAANG and co). So there are companies that can keep your data safe. They're just vanishingly few.

Wasn’t Google revealed to be getting tapped at unencrypted points in its network by the Snowden leaks? I’m guessing they had way way more than 6tb of emails stolen by that program.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#46
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

With social engineering anything can be compromised, online or off. Online just gets more convenient seeing how you never have to leave your location.

I came across an interesting slide deck one time that had various examples of social engineering used in corporate settings to acquire data online and in person. A clever individual can get their hands on just about anything if they try.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#47

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

There is almost no information about this company. I did a passive recon and this is what I've got: https://recon.secapps.com/f/EMh9

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#48

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

I've looked over their website and I'm confused about what they actually do. They are "trusted by leading Fortune 500 corporations" apparently (with logos for Microsoft and Amazon), but the entire "Interested in our solutions" section is a sign up form. What am I signing up for? It's unusual for a company to barely try to promote their products.

They’re most famous for their hypervisor and virtualized desktop software.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#49
Citrix... mention that to any Hungarian programmer roughly my age and you will likely receive a long string of swearing because the incredibly buggy central system necessary to sign up for courses and exams was only accessible via the Citrix ICA client and back in the second half of the 90s that, in itself, was a huge source of problems beyond the server app not being particularly high quality especially on Linux which was rather important because at this time practically all sane IT students were running Linux to access the Internet (remember, we are talking pre-Windows 2000).

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#50

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

It’s absolutely reasonable to be critical of any accusations that “Iran did it” or any other nation that the US considers enemies. Didn’t our security ministers claim North Korea was behind the Sony hacks when Obama was in office? We were never given any proof, so it’s impossible to verify... When you consider the way we lie on international affairs, all statements our government makes must be considered suspect. Thi…

In Liar’s Poker, the author said Wall Street would always blame the Arabs for any unpredicted movement in the finance markets.

Zero evidence, but most Americans didn’t know any personally but knew they had oil money to buy/sell investments.

Post reply on HN