Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

151–160 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#151
post #57

It says they had to find out from the FBI. At least theoretically, how does the FBI find out? (unless someone knows the actuality and is willing to share? Didn't see anything in the article)

Not so sure about that. I use ShareFile for secure document delivery and they forced a password reset with stricter requirements in January, the month after the first breach, and two months before the FBI notification. No notice of breached documents to its customers yet.

Almost as if they didn't force the reset because of the breach, but because of the reason they gave back then?

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#152

Earlier quoted context omitted.

Interesting question. Technically, it is public. The user didn’t break anything or use any nefarious techniques. The web server is configured to list directories which in concert with file permissions makes it public. Not sure how/if this might be analogous to “just because a door isn’t locked doesn’t mean you can go in”.

This argument is not much different than what the grandparent is referring to. weev was convicted of conspiracy to access a computer without authorization because he advised a guy who discovered a publicly available HTTP API hosted by AT&T that returned email addresses based on guessable ids. The conviction was overturned, but on procedural grounds, not legal ones.

Directory listing wasn't on on the AT&T server.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#153
post #85
post #19

Earlier quoted context omitted.

I work with digitisation in the public sector of Denmark. We’ve digitised our elections, but we’ve digitised the part that makes sense, the registration you do before you’re handed you ballot. In the old days, we used to have big books where you’d get crossed off after you were identified. This naturally takes a lot of time, so today we print a little bar code on the piece of paper that we mail every adult citizen at…

There's another way to use computers to help with voting. Have Ballots with a unique identifier. People come to a polling station, get a ballot, fill in their vote. The ballot goes through a scanner to tally the vote, and then goes into a standard vote bin. At the end of voting, you cross-check a random sample (both ways) and check the total number of votes matches between the scanner and bin. If all goes well, scann…

This requires you to put the trust with one person/entity.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#154

Earlier quoted context omitted.

I've looked over their website and I'm confused about what they actually do. They are "trusted by leading Fortune 500 corporations" apparently (with logos for Microsoft and Amazon), but the entire "Interested in our solutions" section is a sign up form. What am I signing up for? It's unusual for a company to barely try to promote their products.

Yes, it makes you wonder, how does a small company pop into existence straight into class-A office space in downtown LA, and within the span of what? two years? claims to have done business with a dozen or so heavyweight companies. And what is their web presence? Vague, inscrutable C-suite-speak about security, and one blockbuster claim in the Citrix break. At some point, Occam's razor will favor that this company is…

The address "555 West 5th St, Los Angeles, California" has a WeWork space in it.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#155
post #113
post #104

Ah, The Register lifting another story from another news outlet. The original report came from NBC: https://www.nbcnews.com/politics/national-security/iranian-b... Which The Register didn't bother to credit. I swear, this site is now no worse than an Indian blog. Every site online credited NBC except these "journalism experts" (to be red clickbait-loving, content thieving d-bags)

>> Which The Register didn't bother to credit. I swear, this site is now no worse than an Indian blog. That seems uncalled for. Are Indian blogs (as opposed to non-Indian blogs) known for this kind of thing?

Yes

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#156

Earlier quoted context omitted.

It’s absolutely reasonable to be critical of any accusations that “Iran did it” or any other nation that the US considers enemies. Didn’t our security ministers claim North Korea was behind the Sony hacks when Obama was in office? We were never given any proof, so it’s impossible to verify... When you consider the way we lie on international affairs, all statements our government makes must be considered suspect. Thi…

I think it is best to take a wholesale view that the news as we know it is a religion. That sounds a bit odd given that a lot that is in the news is fact oriented and a lot of current affairs is discussed. But in a formal church there is mention and prayers for those caught up in actual events. Fundamentally though the news requires belief. It is there for the 'capitalist flock' who have a world where the government,…

One could also describe it simply as a tautology. It comes with its own simplified, illusory cause/effect chain and line of reasoning based off of itself, without necessitating the same "feeling" or "spiritual" sensibilities as most religions or cult movements.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#157

Earlier quoted context omitted.

It’s absolutely reasonable to be critical of any accusations that “Iran did it” or any other nation that the US considers enemies. Didn’t our security ministers claim North Korea was behind the Sony hacks when Obama was in office? We were never given any proof, so it’s impossible to verify... When you consider the way we lie on international affairs, all statements our government makes must be considered suspect. Thi…

> We were never given any proof, so it’s impossible to verify... Bullshit. https://www.nytimes.com/2015/01/19/world/asia/nsa-tapped-int... https://www.recode.net/2015/4/21/11561700/sony-hack-was-not-... https://www.symantec.com/connect/blogs/collaborative-operati... https://www.nytimes.com/2018/09/06/us/politics/north-korea-s...

None of the articles you linked offered any proof but rather just accusations mostly more accusations from American companies too I may add. “While the need to protect sensitive sources and methods precludes us from sharing all of this information, our conclusion is based, in part, on the following: Then it goes into some vague details about how it happened proving nothing. So again we have to take their word this is the truth. Perhaps it is but show us the hard truth. De-classify the documents that show the links. Again it is all “believe us we can link it to North Korea”.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#158
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

> I wouldn't put personal data I am not willing to lose online or on an intranet at all anymore Anymore? Not trusting the internet used to be the default.

Note that he said "intranet" (not "internet"), which had historically been presumed to be limited to internal access only. I think his point is valid and a little alarming.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#159
post #24

Earlier quoted context omitted.

Are you the CEO of a company that works in computer security, where fame is probably more important than in other fields?

Fame does not equal trust. While there may not be any security through obsecurity it is a barrier. As for being a trusted CEO at a certain point its about who you know and who knows you. Do you think the NSA employees all have social media profiles?

[deleted]

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#160
post #96
post #75

Earlier quoted context omitted.

[flagged]

You're downvoted, because you seem to be whitewashing a few things - from Assad, to Soviets in Afghanistan, in your quest to paint USA blacker. You tell us to take intelligence community with a grain of salt, and then speculate about Kashoggi - where most information comes from Turkey's intelligence aparatus. Also socialists are also funded and armed by USA (see SDF in Syria). Also this guy (armed by USA) - https://e…

I agree regarding “whitewashing” the Soviet presence in Afghanistan, for example. But it was skipping over that to make a point - we occupied the country and did the exact same thing as the Soviets, for longer than they did, on our own dime, and encountered the same kind of resistance that we formerly supported. Whatever the reasons for the Soviet coup in 1979, our actions post 9/11 combined with our actions then show a schitzophrenic foreign policy.

Socialists and Shiites were obviously occasionally funded and armed by the USA, and I even alluded to this - Saddam was a socialist, and the new government of Iraq was a Shiite government. However, that doesn’t negate what I said - read it carefully. Far more mainstream sources than me have pointed this out:

http://www.cc.com/video-clips/yt7an7/the-daily-show-with-jon...

Post reply on HN