Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

61–70 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#61

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Slightly less cynical explanation, could it be a parallel construction type thing? Something like: The FBI (or whoever) have espionage on whichever groups and heard data from Citrix being discussed, but they don’t want to reveal that espionage so they reveal it through Resecurity.

I wouldn't rule it out completely but both Hanlon's and Occam's razor would point against it. More likely that it's just another cybersec company that has found a way to newsjack itself into a position of fame via premature attribution.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#62
post #43

Earlier quoted context omitted.

My counter-point to this would be that we haven't seen significant breaches (at least, not on the scale of this) from the tech giants (FAANG and co). So there are companies that can keep your data safe. They're just vanishingly few.

Wasn’t Google revealed to be getting tapped at unencrypted points in its network by the Snowden leaks? I’m guessing they had way way more than 6tb of emails stolen by that program.

Yes. But it's also true that if you live in a country with a lot of powerful intelligence agencies, and one of those intelligence agencies wants access to your data, they will get it through some means or another. It doesn't really matter how secure your practices are.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#63

Earlier quoted context omitted.

I've looked over their website and I'm confused about what they actually do. They are "trusted by leading Fortune 500 corporations" apparently (with logos for Microsoft and Amazon), but the entire "Interested in our solutions" section is a sign up form. What am I signing up for? It's unusual for a company to barely try to promote their products.

They’re most famous for their hypervisor and virtualized desktop software.

I think GP is asking about the security company, not Citrix.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#64

Earlier quoted context omitted.

Wasn’t Google revealed to be getting tapped at unencrypted points in its network by the Snowden leaks? I’m guessing they had way way more than 6tb of emails stolen by that program.

Yes. But it's also true that if you live in a country with a lot of powerful intelligence agencies, and one of those intelligence agencies wants access to your data, they will get it through some means or another. It doesn't really matter how secure your practices are.

By using Google you are defacto tapped. But if you use a small provider, you'll only be tapped if they can be bothered with you, which for the average folk is quite unlikely.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#65

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies

[1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-releases/resecurity-names-ia... [3] https://www.businesswire.com/news/home/20190226005414/en/Res... [4] https://goldenbridgeawards.com/store/

Looks like a fish, smells like a fish

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#66
post #56
post #24

Earlier quoted context omitted.

Are you the CEO of a company that works in computer security, where fame is probably more important than in other fields?

To be fair, conceptually the concept of a CEO of a security company with no social media presence at all is not surprising, speaking from my experience with people in this field.

This is often overlooked. If your kid wants to work in security it will be hard to get a job if his/her info and history can be found on social media.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#67

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Agreed that something seems off. Generous interpretation - they're brand new (first Tweet 2/13/2019, first blog 2/19/2019). Would love to know if those logos & awards are legit (quick search of the awards makes some look like pay to win).

The FAQ page: How Can I Improve my Chances of Receiving an Award?

One answer is: Sponsor the Cybersecurity Excellence Awards

There's a voting scheme, but the FAQ does state: The popular vote will only be considered if two or more nomination are tied for an award

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#68
post #19

Earlier quoted context omitted.

Now extend that to voting systems too... not just folly, but criminal insanity.

I work with digitisation in the public sector of Denmark. We’ve digitised our elections, but we’ve digitised the part that makes sense, the registration you do before you’re handed you ballot. In the old days, we used to have big books where you’d get crossed off after you were identified. This naturally takes a lot of time, so today we print a little bar code on the piece of paper that we mail every adult citizen at…

In Australia we have the staff still ruling us off in the electoral role. That usually takes a minute or less. The entire voting process (including queuing) depends upon the popularity of the individual voting booth and time of day, but is usually less than 10 minutes. This may be because there are an adequate number of booths and trained staff.But it is also because of compulsory voting. The highly likely attendance numbers per booth and their distribution across the day are known and can be planned for, unlike some other more random systems.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#69
post #39

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Good catch, that is called a 3 letter agency front.

Absolutely this. Have encountered them before.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#70
“Resecurity also said it warned Citrix on December 28...” And then: “Citrix, meanwhile, said it took action – launching an internal probe and securing its networks – after hearing from the FBI earlier this week.”

Putting aside the fact this security company seems to have never been heard of before; Citrix’s appears to have buried their heads in the sand until the Feds came knocking.

If it’s true that the company was tipped off in December then the ‘I know nothing’ defence is truly shocking.

Post reply on HN