Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

181–190 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#181
post #180

Earlier quoted context omitted.

FYI, PRNewswire is one of the oldest, respected, and expensive newswire services around. Businesswire is also very well established. Not sure how those seem “suspicious”.

Not sure if that was meant to be sarcastic. They have a pretty clear history of accepting garbage for money. https://www.seroundtable.com/google-panda-pr-newswire-change...

PRNewswire is used by the vast majority of the Fortune 1000, including for releases that are required for SEC compliance. They are probably the oldest and most widely used of all the newswire services.

The point is that using PRNewswire or Businesswire is hardly “suspicious,” because most businesses that do press releases use one or the other.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#182
post #113
post #104

Ah, The Register lifting another story from another news outlet. The original report came from NBC: https://www.nbcnews.com/politics/national-security/iranian-b... Which The Register didn't bother to credit. I swear, this site is now no worse than an Indian blog. Every site online credited NBC except these "journalism experts" (to be red clickbait-loving, content thieving d-bags)

>> Which The Register didn't bother to credit. I swear, this site is now no worse than an Indian blog. That seems uncalled for. Are Indian blogs (as opposed to non-Indian blogs) known for this kind of thing?

I assume there's tons of Indian blogs that are just fine, but for some reason most of the time I see blog posts without any depth but full of buzz words being spammed around, they're written by someone from India (and less often Pakistan).

Now it could be that this is just purely because because there's more Indian blogs, making the percentage of spam blogs higher, or because there's three or four people spamming their useless blogs everywhere, but I do hesitate to click blogs with the .in TLD these days.

Probably just a few assets ruining for the whole group, but in my circle Indian blogs do tend to have a bad rep.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#183
post #16

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

I don't have a LinkedIn page, or any other social media for this matter. Does that make me a non-trusrworthy person now? This is horrible. (I don't disagree with your other points).

+1, I also recently deleted my LinkedIn profile. Taking LinkedIn profile as a sign of authenticity is indeed horrible.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#184

Earlier quoted context omitted.

OK, so there's a Yahoo! breach from 2012. Should I not visit Yahoo now? Also please note the '?' marks for unverified sources.

There is a difference between not liking the OC's idea of an extension, and saying that HIBP does not have the data required to make such an extension. First you said the latter, now you're saying the former. Own up to your mistakes.

You are correct, I souldn't be arguing to you on OC's idea. Thank you.

But I didn't say HIBP doesn't have these data. My point is these data isn't enough to give recommendations or warnings to site visitors.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#185
post #119

Earlier quoted context omitted.

Truly free people are free to keep all the secrets they want.

The only reason to keep secrets is if they aren't free. Otherwise the secret protects nothing. Freedom is broad and self contradictory. Complete freedom for more than one person is impossible.

That's not true. There are any number of subgroups that view certain behavior with distaste that other subgroups do not. Just because there is social and cultural pressure to do or not do things doesn't mean you are unfree. You are just as free to observe the behaviors or not as other people are to judge you by them.

I mean, I don't like tipping. I think it's horrible in many aspects, not the least of which how it taps directly into racial and gender prejudices monetarily (black waiters make less in tips regardless of service level). That said, I tip. I would rather not be known as the guy that doesn't tip (and wages assume tips as of now, so it's a bit unfair to the service people). I'm still free to tip or not, and others are free to judge or misjudge me for it if I do.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#186
post #135

Earlier quoted context omitted.

OK, so there's a Yahoo! breach from 2012. Should I not visit Yahoo now? Also please note the '?' marks for unverified sources.

Do you have a better solution than not using a service? Not using it is like voting with your wallet. So yes, I would say stay away from yahoo. Where do we draw a line otherwise? It is the same boat as "I don't like Facebook collecting data on me but I'll still use their service".

Yes, it's in the same boat, we (almost) all do it with Google.

I don't know where to draw a line, but I don't think a single data breach, even minor one, should mean a death sentence to business. Maybe some sort of audit/certification should be mandatory after breach.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#189
post #16

Earlier quoted context omitted.

I don't have a LinkedIn page, or any other social media for this matter. Does that make me a non-trusrworthy person now? This is horrible. (I don't disagree with your other points).

According to 2 companies I interviewed with: Yes. I was pissed because if they didn't trust my resume, why even interview me and waste my time.

You dodged two bullets. Consider yourself lucky.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#190
post #135

Earlier quoted context omitted.

Do you have a better solution than not using a service? Not using it is like voting with your wallet. So yes, I would say stay away from yahoo. Where do we draw a line otherwise? It is the same boat as "I don't like Facebook collecting data on me but I'll still use their service".

Yes, it's in the same boat, we (almost) all do it with Google. I don't know where to draw a line, but I don't think a single data breach, even minor one, should mean a death sentence to business. Maybe some sort of audit/certification should be mandatory after breach.

I think the idea is more about informing users than it is about trying to drum up a boycott that results in a "death sentence".

For example, with regards to search engines, what if I go on Google and it tells me "hey, Google has had 3 data breaches that have effected users like you". And then I go on DuckDuckGo and it says "DDG has never had a data breach". Not everyone will switch from Google to DDG, but some people will, and I don't think that's a bad thing.

Post reply on HN