Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

131–140 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#131

Earlier quoted context omitted.

Is there any risk you take by posting that? That is a page that I doubt the author would have wanted to be public, and is not linked to from the home page or its descendants. Wasn't that the case against weev? (IMO, if it is public, it should be legal to post to it, but whatever.)

Interesting question. Technically, it is public. The user didn’t break anything or use any nefarious techniques. The web server is configured to list directories which in concert with file permissions makes it public. Not sure how/if this might be analogous to “just because a door isn’t locked doesn’t mean you can go in”.

This argument is not much different than what the grandparent is referring to. weev was convicted of conspiracy to access a computer without authorization because he advised a guy who discovered a publicly available HTTP API hosted by AT&T that returned email addresses based on guessable ids. The conviction was overturned, but on procedural grounds, not legal ones.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#132

Earlier quoted context omitted.

What's suspicious about PR Newswire / Business Wire? They're the industry standard wire tools in Public Relations. The Golden Bridge trophies seem to be available to buy if you've won .

I don’t know specifically about Golden Bridge but I have been on the receiving end of other trophy clearinghouses: we were notified we had won a whatever of the year award without even applying for it and that we could purchase the actual trophy for a very reasonable price. Basically these companies’ business is selling overpriced crystal trinkets.

As have I, it's a fairly common racket. However, rights to a trophy / rights to use the logo etc are also sold by perfectly legitimate awards too.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#133
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

We need to make companies criminally liable for this information if it gets stolen. If they can’t secure it, don’t collect it.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#134
post #49

Citrix... mention that to any Hungarian programmer roughly my age and you will likely receive a long string of swearing because the incredibly buggy central system necessary to sign up for courses and exams was only accessible via the Citrix ICA client and back in the second half of the 90s that, in itself, was a huge source of problems beyond the server app not being particularly high quality especially on Linux whi…

The amazing part to me is that it still sucks: it’s 2019 and random hangs requiring a full session restart are still a daily occurrence, and I recently measured keystroke latency at 130+ms over a LAN. That’s much worse than using X11 over SSH ever was.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#135

Earlier quoted context omitted.

Nope. https://haveibeenpwned.com/PwnedWebsites

OK, so there's a Yahoo! breach from 2012. Should I not visit Yahoo now? Also please note the '?' marks for unverified sources.

Do you have a better solution than not using a service? Not using it is like voting with your wallet. So yes, I would say stay away from yahoo. Where do we draw a line otherwise? It is the same boat as "I don't like Facebook collecting data on me but I'll still use their service".

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#136

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

And to add to it, their facebook page only has 20 likes. Their first post is dated 14 feb 2019 with over 10,000 engagement (likes, reactions), while their post the next day has only 1 like.

Also their fan club looks to be mainly from Thailand (not english speakers from the profile names). Definitely a few red flags.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#137
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

We need to make companies criminally liable for this information if it gets stolen. If they can’t secure it, don’t collect it.

This was the approach of the game site GoG at first. The user had no choice to save their payment preference (e.g. credit card) and they explained the reason was that it's impossible for hackers to get the info if they don't store it in the first place. It was a refreshing approach at the time for me (~2007) They've since given the option to save but it's optional.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#138
post #88
post #82

Earlier quoted context omitted.

Unsecured directory listing of a common php cms that shows uploads, and one of them them is a full DB dump made with phpmyadmin. The only thing missing is execution rights in that directory. This is either an insider joke or a jump back to 2004.

this is "wordpress-normal" - the funny/sad part is its the wordpress blog of a security company investigating a huge breach...

I've never seen directory listing turned on as a normal part of WP install.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#139
post #66
post #56

Earlier quoted context omitted.

To be fair, conceptually the concept of a CEO of a security company with no social media presence at all is not surprising, speaking from my experience with people in this field.

This is often overlooked. If your kid wants to work in security it will be hard to get a job if his/her info and history can be found on social media.

Sorry but unless there is a good reason for it, a lack of social media presence is a red flag when hiring- especially for tech positions.

In saying that, if a candidate do have too many public posts showing poor judgment (e.g. hard partying, drunk photos) it will make it definitely make them less in demand.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#140
post #76
post #65

Earlier quoted context omitted.

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

[deleted]
Post reply on HN