Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

81–90 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#81

Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad. It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of c…

I suspect some places still only use passwords for server logins because they can simply use active directory for user management and then have servers use ad/ldap for credential checking.

I think businesses with critical infrastructure should use hardware keys (e.g. yubikeys) to provide at least one of the factors needed to log in to a server. Using a yubikey as an authentication key for ssh is not that difficult and I do it for my own hobby stuff.

For web based stuff one can now use webauthn to provide key based authentication (in addition to whatever other factors one would like). This requires the enterprise to run up to date browser however.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#82
post #76
post #65

Earlier quoted context omitted.

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

Unsecured directory listing of a common php cms that shows uploads, and one of them them is a full DB dump made with phpmyadmin. The only thing missing is execution rights in that directory.

This is either an insider joke or a jump back to 2004.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#83
post #66
post #56

Earlier quoted context omitted.

To be fair, conceptually the concept of a CEO of a security company with no social media presence at all is not surprising, speaking from my experience with people in this field.

This is often overlooked. If your kid wants to work in security it will be hard to get a job if his/her info and history can be found on social media.

No it won't, that's a really odd take. Perhaps if you want a job in very specific sub-section of cyber-espionage stuff, you might have a problem with existing on social media (although I doubt it)

But the idea that general IT security companies have a reduced chance of hiring someone based on their information being on social media is... not the case.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#84
post #24

Earlier quoted context omitted.

Are you the CEO of a company that works in computer security, where fame is probably more important than in other fields?

Fame does not equal trust. While there may not be any security through obsecurity it is a barrier. As for being a trusted CEO at a certain point its about who you know and who knows you. Do you think the NSA employees all have social media profiles?

Fame doesn't equal trust, but if someone with no public background starts claiming to have been in the NSA/MI6/FSB/whatever, why would you believe them?

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#85
post #19

Earlier quoted context omitted.

Now extend that to voting systems too... not just folly, but criminal insanity.

I work with digitisation in the public sector of Denmark. We’ve digitised our elections, but we’ve digitised the part that makes sense, the registration you do before you’re handed you ballot. In the old days, we used to have big books where you’d get crossed off after you were identified. This naturally takes a lot of time, so today we print a little bar code on the piece of paper that we mail every adult citizen at…

There's another way to use computers to help with voting.

Have Ballots with a unique identifier. People come to a polling station, get a ballot, fill in their vote.

The ballot goes through a scanner to tally the vote, and then goes into a standard vote bin.

At the end of voting, you cross-check a random sample (both ways) and check the total number of votes matches between the scanner and bin.

If all goes well, scanner results get electronically combined. If the sampling shows an error, count by hand.

One extra addition. Your ballot is filled out by a separate printer. This ensures proper readability at the scanner, and allows placing the unique ID after someone gave you the ballot (to keep your vote secret). Any tampering with non-unique IDs is detectable by the random sampling.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#86
post #19

Earlier quoted context omitted.

I work with digitisation in the public sector of Denmark. We’ve digitised our elections, but we’ve digitised the part that makes sense, the registration you do before you’re handed you ballot. In the old days, we used to have big books where you’d get crossed off after you were identified. This naturally takes a lot of time, so today we print a little bar code on the piece of paper that we mail every adult citizen at…

In Australia we have the staff still ruling us off in the electoral role. That usually takes a minute or less. The entire voting process (including queuing) depends upon the popularity of the individual voting booth and time of day, but is usually less than 10 minutes. This may be because there are an adequate number of booths and trained staff.But it is also because of compulsory voting. The highly likely attendance…

And the other great part is the democracy sausage at the event!

Although my local polling booth didn't have a bbq going which was kind of disappointing.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#87
post #66
post #56

Earlier quoted context omitted.

To be fair, conceptually the concept of a CEO of a security company with no social media presence at all is not surprising, speaking from my experience with people in this field.

This is often overlooked. If your kid wants to work in security it will be hard to get a job if his/her info and history can be found on social media.

This is not true.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#88
post #82
post #76

Earlier quoted context omitted.

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

Unsecured directory listing of a common php cms that shows uploads, and one of them them is a full DB dump made with phpmyadmin. The only thing missing is execution rights in that directory. This is either an insider joke or a jump back to 2004.

this is "wordpress-normal" - the funny/sad part is its the wordpress blog of a security company investigating a huge breach...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#89
post #76
post #65

Earlier quoted context omitted.

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

Nice find. It contains the e-mail address mr.archee@gmail.com

Which seems to belong to a russian guy: https://support.webasyst.ru/forum/4011/filtr-v-vide-select/

Must be a russian speaking Iranian ;-)

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#90
post #75

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

[flagged]

Assad is using chemical weapons against his own people. It was determined by OPCW. You can read full reports of the two well publicized attacks here:

https://www.opcw.org/fileadmin/OPCW/Fact_Finding_Mission/s-1...

https://www.opcw.org/sites/default/files/documents/2019/03/s...

But there were many more. So please don't spread unsubstantiated falsehoods and doubt.

Post reply on HN