Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

141–150 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#141
post #78
post #73

Earlier quoted context omitted.

How did we come to this imbalance?

State secrecy being used as an excuse for violence. A truly free people keep no secrets.

Yes. US government should publish it's nuclear launch codes on whitehouse.gov

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#144
post #88
post #82

Earlier quoted context omitted.

Unsecured directory listing of a common php cms that shows uploads, and one of them them is a full DB dump made with phpmyadmin. The only thing missing is execution rights in that directory. This is either an insider joke or a jump back to 2004.

this is "wordpress-normal" - the funny/sad part is its the wordpress blog of a security company investigating a huge breach...

Unless this is actually not a security company investigating a huge breach.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#145
post #57

It says they had to find out from the FBI. At least theoretically, how does the FBI find out? (unless someone knows the actuality and is willing to share? Didn't see anything in the article)

Not so sure about that.

I use ShareFile for secure document delivery and they forced a password reset with stricter requirements in January, the month after the first breach, and two months before the FBI notification.

No notice of breached documents to its customers yet.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#146

Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad. It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of c…

Citrix's secure document delivery product, ShareFile, sent emails to all its document recipients forcing a password reset with stricter requirements in January.

We aren't getting the whole story from Citrix.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#148

Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad. It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of c…

Same tactic as what's used on Twitter accounts. And same as I said previously: If the bad actors can brute force weak passwords, the company itself should be able to do it too and force those with weak passwords to update them.

Interestingly enough, Citrix ShareFile forced password resets for everyone in January.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#149

Earlier quoted context omitted.

I suspect some places still only use passwords for server logins because they can simply use active directory for user management and then have servers use ad/ldap for credential checking. I think businesses with critical infrastructure should use hardware keys (e.g. yubikeys) to provide at least one of the factors needed to log in to a server. Using a yubikey as an authentication key for ssh is not that difficult an…

> This requires the enterprise to run up to date browser however. Why is this so hard?!? I agree with you, but this sentence rang so true it was sad. I've been forced to work with/around unbelievably out-of-date browsers in order to install current firmware updates on systems at almost every place I've worked. /rant

Because large corporations have teams in charge of users desktops that still assume this is the 90s, and most users are idiots. Also, there are a ton of bad internal web applications targetting outdated browsers

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#150
post #13

>> Earlier today, Citrix chief information security officer Stan Black gave his company's side of the story. He said that, as of right now, Citrix does not know exactly which documents the hackers obtained nor how they got in... Ouch. The winner of "The worst position to be in today".

And, IMO, they've known about it since January when they abruptly forced password resets on every ShareFile user. I use ShareFile for secure delivery of documents containig DOB, SSN, AGI, ...

No notice from Citrix ShareFile to its customers about a breach yet, though. Thanks.

Post reply on HN