Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

161–170 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#161

Earlier quoted context omitted.

Fame does not equal trust. While there may not be any security through obsecurity it is a barrier. As for being a trusted CEO at a certain point its about who you know and who knows you. Do you think the NSA employees all have social media profiles?

Fame doesn't equal trust, but if someone with no public background starts claiming to have been in the NSA/MI6/FSB/whatever, why would you believe them?

[deleted]

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#164
post #76
post #65

Earlier quoted context omitted.

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

Nice. According to the wp_users table there are 3 users, all nearly exactly 1 year old (2018-03-03, 2018-03-05, 2018-03-17).What are the chances that's a coincidence?

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#165
At this point, it is (or should be) absolutely clear that password security is a top priority for everyone nowadays. The only solution that I have heard of is password managers, but what if such companies are hacked like this one? I am curious if we will eventually recommend randomly generating passwords per website and keeping them under lock and key (physically so such as in a safe).

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#166
post #157

Earlier quoted context omitted.

> We were never given any proof, so it’s impossible to verify... Bullshit. https://www.nytimes.com/2015/01/19/world/asia/nsa-tapped-int... https://www.recode.net/2015/4/21/11561700/sony-hack-was-not-... https://www.symantec.com/connect/blogs/collaborative-operati... https://www.nytimes.com/2018/09/06/us/politics/north-korea-s...

None of the articles you linked offered any proof but rather just accusations mostly more accusations from American companies too I may add. “While the need to protect sensitive sources and methods precludes us from sharing all of this information, our conclusion is based, in part, on the following: Then it goes into some vague details about how it happened proving nothing. So again we have to take their word this is…

You simply gave a summary of the first article's summary and then falsely claimed there were no details.

The articles are summaries of what the government and the companies discovered. Read the indictment linked in the last article or the reports from the companies for details.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#167
post #19

Earlier quoted context omitted.

Now extend that to voting systems too... not just folly, but criminal insanity.

I work with digitisation in the public sector of Denmark. We’ve digitised our elections, but we’ve digitised the part that makes sense, the registration you do before you’re handed you ballot. In the old days, we used to have big books where you’d get crossed off after you were identified. This naturally takes a lot of time, so today we print a little bar code on the piece of paper that we mail every adult citizen at…

> does speed of counting really matter?

That's a great question. The answer depends a little bit on how many issues are on the ballot, and a hell of a lot more on whether you're asking the media, or those with a direct stake in the outcome, or those voters. Your system is optimized to serving voters.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#168
post #24

Earlier quoted context omitted.

Are you the CEO of a company that works in computer security, where fame is probably more important than in other fields?

Fame does not equal trust. While there may not be any security through obsecurity it is a barrier. As for being a trusted CEO at a certain point its about who you know and who knows you. Do you think the NSA employees all have social media profiles?

Fame doesn't equal trust, but trust over time does create recognition (perhaps fame is a bit too strong). My claim is that if no one can vouch for you, how can I trust you?

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#169
post #65

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

They also seem to have stolen a number of graphics on their website. If you check their filenames, they have the default filename of when you take a screenshot on OSX. Then take this one for example:

https://resecurity.com/wp-content/uploads/2019/03/Screen-Sho...

Throw it into Google's reverse image search and you'll find the graphic if was cut out of:

https://www.incimages.com/uploaded_files/image/970x450/Finan...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#170

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Neither the US government nor Citrix have implicated Iran. Resecurity came out of the woodwork contacting media companies about its supposed research after Citrix posted a brief statement explaining the FBI had notified it of a breach.

The same company also blamed a hack in Australia on Iran, which the Australian government does not agree with. https://www.itwire.com/security/86141-iran-or-china-competin...
Post reply on HN