Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

111–120 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#111
post #78
post #73

Earlier quoted context omitted.

How did we come to this imbalance?

State secrecy being used as an excuse for violence. A truly free people keep no secrets.

In the sense that free people would still be free if all their secrets are exposed? I can get behind that train of thought.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#112
post #88

Earlier quoted context omitted.

this is "wordpress-normal" - the funny/sad part is its the wordpress blog of a security company investigating a huge breach...

Well, its better to get some wordpress hacked, than it is to have a server onprem get pwned and used as a inadvertent bastion to your internal network.

[deleted]

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#113
post #104

Ah, The Register lifting another story from another news outlet. The original report came from NBC: https://www.nbcnews.com/politics/national-security/iranian-b... Which The Register didn't bother to credit. I swear, this site is now no worse than an Indian blog. Every site online credited NBC except these "journalism experts" (to be red clickbait-loving, content thieving d-bags)

>> Which The Register didn't bother to credit. I swear, this site is now no worse than an Indian blog.

That seems uncalled for. Are Indian blogs (as opposed to non-Indian blogs) known for this kind of thing?

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#115
post #78

Earlier quoted context omitted.

State secrecy being used as an excuse for violence. A truly free people keep no secrets.

In the sense that free people would still be free if all their secrets are exposed? I can get behind that train of thought.

If you allow your government to keep its own secrets, it will use that right to rule you.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#116
post #76

Earlier quoted context omitted.

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

Is there any risk you take by posting that? That is a page that I doubt the author would have wanted to be public, and is not linked to from the home page or its descendants. Wasn't that the case against weev? (IMO, if it is public, it should be legal to post to it, but whatever.)

[deleted]

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#117
post #76

Earlier quoted context omitted.

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

Is there any risk you take by posting that? That is a page that I doubt the author would have wanted to be public, and is not linked to from the home page or its descendants. Wasn't that the case against weev? (IMO, if it is public, it should be legal to post to it, but whatever.)

Interesting question. Technically, it is public. The user didn’t break anything or use any nefarious techniques. The web server is configured to list directories which in concert with file permissions makes it public. Not sure how/if this might be analogous to “just because a door isn’t locked doesn’t mean you can go in”.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#118
post #65

Earlier quoted context omitted.

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

What's suspicious about PR Newswire / Business Wire? They're the industry standard wire tools in Public Relations. The Golden Bridge trophies seem to be available to buy if you've won .

Only fake awards sell trophies. they give the award to everything and make money in trophy sales. See also SuperDoctors, Who's Who, and pay to publish journals with no peer reviews.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#119
post #78

Earlier quoted context omitted.

State secrecy being used as an excuse for violence. A truly free people keep no secrets.

Truly free people are free to keep all the secrets they want.

The only reason to keep secrets is if they aren't free. Otherwise the secret protects nothing. Freedom is broad and self contradictory. Complete freedom for more than one person is impossible.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#120
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

> I wouldn't put personal data I am not willing to lose online or on an intranet at all anymore Anymore? Not trusting the internet used to be the default.

I was at Barnes and Noble yesterday and on an end, I saw an "internet password log book" for $5.98.

A few years ago, I soughed at it, poking fun at it.

Now, it's not a bad idea.

Post reply on HN