Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

51–60 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#51

Earlier quoted context omitted.

Totally agree. My guess — and it’s obviously nothing more than that — is that they don’t fully know yet, but it might seem better and easier to solve than the alternative that there’s very little organizations in this position can ever actually do to prevent sophisticated attacks.

The fact they were unaware about the breach until FBI told them says much. It's not that easy to exfiltrate 6TB of data unnoticed if you have any IDS (automated or just manual) in place.

Having an IDS in place means jack shit if you don’t have skilled personnel managing it.

Depressingly often, these things are installed as part of a box ticking exercise to pass an audit or meet another form of compliance. however they never get set up right from the outset or the security professionals who were there leave and never get replaced.

In this case, if they’re talking about infrastructure available on the public internet with password only authentication then I’d wager any skilled professionals they may or may not have had, had already left. Because no security minded engineer would have okayed that practice. Which means even if they did have an IDS, I’m highly doubtful that would have been managed properly either.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#53

“Threat actors”. What’s wrong with the word “perpetrator” or simply “criminal”?

In addition to other comments : I guess "threat actors" includes non-human autonomous hacking systems ("AI"), and humans (or organizations) who are neither good or bad intended, but whose actions happen to have negative consequences.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#54
post #49

Citrix... mention that to any Hungarian programmer roughly my age and you will likely receive a long string of swearing because the incredibly buggy central system necessary to sign up for courses and exams was only accessible via the Citrix ICA client and back in the second half of the 90s that, in itself, was a huge source of problems beyond the server app not being particularly high quality especially on Linux whi…

Sounds like any university Reg system.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#55
post #43
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

My counter-point to this would be that we haven't seen significant breaches (at least, not on the scale of this) from the tech giants (FAANG and co). So there are companies that can keep your data safe. They're just vanishingly few.

They've definitely had breaches, which while obviously their containment was a bit better, leads me to believe they're not any less susceptible in the long run.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#56
post #24
post #16

Earlier quoted context omitted.

I don't have a LinkedIn page, or any other social media for this matter. Does that make me a non-trusrworthy person now? This is horrible. (I don't disagree with your other points).

Are you the CEO of a company that works in computer security, where fame is probably more important than in other fields?

To be fair, conceptually the concept of a CEO of a security company with no social media presence at all is not surprising, speaking from my experience with people in this field.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#58

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

You can hide your linkedin history from people that are not connected to you (or your whole profile). It's a privacy option.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#59
post #16

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

I don't have a LinkedIn page, or any other social media for this matter. Does that make me a non-trusrworthy person now? This is horrible. (I don't disagree with your other points).

the point is that there is a LinkedIn page. But all employees are directors or VP's - not a single engineer that works at Rsecurity.

Unlikely that they are a front to a US operation. But very likely that it's a start-up that leverages the currently toxic climate in order to get themselves in the news. Making half baked attribution claims is a perfect way to do so. One might even say that not doing so would be leaving money on the table.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#60

Earlier quoted context omitted.

I've looked over their website and I'm confused about what they actually do. They are "trusted by leading Fortune 500 corporations" apparently (with logos for Microsoft and Amazon), but the entire "Interested in our solutions" section is a sign up form. What am I signing up for? It's unusual for a company to barely try to promote their products.

They’re most famous for their hypervisor and virtualized desktop software.

That's what Citrix is famous for - that's not the company I was talking about.
Post reply on HN