Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

191–200 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#191
post #9

Shares of Citrix is down after report of hack: https://www.cnbc.com/2019/03/08/citrix-tumbles-on-report-of-...

But still higher than they were Dec 24th 2018. Actually higher than they were at any point prior to April 2018. Because the market knows that major security breaches that will have long-lasting impact on the victims involved will ultimately have no impact on the company that was breached.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#192
post #85
post #19

Earlier quoted context omitted.

I work with digitisation in the public sector of Denmark. We’ve digitised our elections, but we’ve digitised the part that makes sense, the registration you do before you’re handed you ballot. In the old days, we used to have big books where you’d get crossed off after you were identified. This naturally takes a lot of time, so today we print a little bar code on the piece of paper that we mail every adult citizen at…

There's another way to use computers to help with voting. Have Ballots with a unique identifier. People come to a polling station, get a ballot, fill in their vote. The ballot goes through a scanner to tally the vote, and then goes into a standard vote bin. At the end of voting, you cross-check a random sample (both ways) and check the total number of votes matches between the scanner and bin. If all goes well, scann…

IDs on ballots don't make sense. You cannot know your ID without breaking a requirement for good free voting systems: It shall not be possible to prove to others how you voted. This is to prevent forcing or purchasing votes.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#193
post #134
post #49

Citrix... mention that to any Hungarian programmer roughly my age and you will likely receive a long string of swearing because the incredibly buggy central system necessary to sign up for courses and exams was only accessible via the Citrix ICA client and back in the second half of the 90s that, in itself, was a huge source of problems beyond the server app not being particularly high quality especially on Linux whi…

The amazing part to me is that it still sucks: it’s 2019 and random hangs requiring a full session restart are still a daily occurrence, and I recently measured keystroke latency at 130+ms over a LAN. That’s much worse than using X11 over SSH ever was.

It’s been pretty much a law of software for me that once an app is primarily business to business and gets traction in the Fortune 500 expect the functionality to stay the exact same or become worse over the next 10 years

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#194

I am not very well informed. How serious is this?

Depending on what was obtained, very serious and with potential for ongoing problems.

If this impacted their software development, it could include source for current and older but still in use products, which could potentially be analyzed looking for potential exploits. It may include internal bug trackers that may include information on unpatched exploits or on exploits quietly patched only as part of updates and so potentially still in the wild. Heck, it may include some of their internal product security testing information and whatever might be in that.

An awful lot of large companies and healthcare systems now have Citrix portals available to the world rather than having annoying-to-manage-and-support VPN connections - are there undisclosed vulnerabilities in any of those?

Even going outside the technical side, if there's sensitive HR information they may have materials that can be leveraged for blackmail purposes to attempt to maintain long-term access.

And all of that is just talking about the Citrix remote access piece that I still think of when I hear the name. There's also XenApp/XenDesktop for virtualization, the ShareFile sharing site that others have mentioned, their endpoint management product, etc. There might even be holdover stuff - what would a copy of out-of-date source code to GoToMyPC be worth?

A lot will depend on the ability of whoever got it to capitalize on it, but assuming this was indeed a nation expect that they'll be able to spend at least some resources.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#195
post #66

Earlier quoted context omitted.

This is often overlooked. If your kid wants to work in security it will be hard to get a job if his/her info and history can be found on social media.

No it won't, that's a really odd take. Perhaps if you want a job in very specific sub-section of cyber-espionage stuff, you might have a problem with existing on social media (although I doubt it) But the idea that general IT security companies have a reduced chance of hiring someone based on their information being on social media is... not the case.

[deleted]

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#196
post #78

Earlier quoted context omitted.

State secrecy being used as an excuse for violence. A truly free people keep no secrets.

Yes. US government should publish it's nuclear launch codes on whitehouse.gov

Conflating nuclear launch code secrets with war crime secrets: this is the problem with Americans today.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#197
post #192
post #85

Earlier quoted context omitted.

There's another way to use computers to help with voting. Have Ballots with a unique identifier. People come to a polling station, get a ballot, fill in their vote. The ballot goes through a scanner to tally the vote, and then goes into a standard vote bin. At the end of voting, you cross-check a random sample (both ways) and check the total number of votes matches between the scanner and bin. If all goes well, scann…

IDs on ballots don't make sense. You cannot know your ID without breaking a requirement for good free voting systems: It shall not be possible to prove to others how you voted. This is to prevent forcing or purchasing votes.

If you place the ID after the ballot is handed out (by a printer that is also used to fill in the ballot). Then this systems still doesn't allow proving of votes.

The ID here is meant to identify a ballot, not a voter. It should probably be something like a UUID. The aim of this system is to allow cross-checking between the scanner and the physical ballots.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#198

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Founded in 1989, Citrix provides SaaS to most of the Fortune 500, with $3B revenue.

Is your theory is that they either destroyed their company (and risked their careers of perhaps 8K employees), because a few fringe actors in the current administration asked them to help pin this on Iran?

Or is your theory that the US government sent 6TB of data on most of the Fortune 500 companies to an adversary, all to justify some conflict? Note: While oil and perceived geopolitical threats have been misused to start wars, I'm unaware that cyber now ranks at that level. Else, we'd treat DPRK hacking the same as missile testing.

Your evidence is that the CEO is not sufficiently networked on linkedin, and their revenue has changed (after the largest tax cut for US corps in world history).

Honestly, I'm at a loss for words. I suggest exercise, a healthy diet, and reflection.

What you've suggested based on this evidence alone is--and I don't use this word lightly--unhinged and unhealthy. I do believe there is reason to be skeptical of US policy towards Iran. I do not think the US government could convince a 3B revenue company to destroy itself (just think of the shareholder lawsuits), all out of naive patriotic loyalty.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#199
post #197
post #192

Earlier quoted context omitted.

IDs on ballots don't make sense. You cannot know your ID without breaking a requirement for good free voting systems: It shall not be possible to prove to others how you voted. This is to prevent forcing or purchasing votes.

If you place the ID after the ballot is handed out (by a printer that is also used to fill in the ballot). Then this systems still doesn't allow proving of votes. The ID here is meant to identify a ballot, not a voter. It should probably be something like a UUID. The aim of this system is to allow cross-checking between the scanner and the physical ballots.

> The ID here is meant to [..]

I got that, but you can still kind of prove it. Your know your ID + your-vote. This is likely the only valid ID+vote combination you can know before results are counted. That's when I'd "ask" you and late verify it.

If you want to verify the machine is working, just put the ballot in the standard bin and add those IDs in the counting phase. That seems fine in principle and make it easy to check the tech is working as intended. You'd end up with having list of all individual votes available, maybe even to the public. I'd be worried about people throwing statistical algorithms at that. You better also find a near perfect method to randomize order...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#200

Earlier quoted context omitted.

Yes, it's in the same boat, we (almost) all do it with Google. I don't know where to draw a line, but I don't think a single data breach, even minor one, should mean a death sentence to business. Maybe some sort of audit/certification should be mandatory after breach.

I think the idea is more about informing users than it is about trying to drum up a boycott that results in a "death sentence". For example, with regards to search engines, what if I go on Google and it tells me "hey, Google has had 3 data breaches that have effected users like you". And then I go on DuckDuckGo and it says "DDG has never had a data breach". Not everyone will switch from Google to DDG, but some people…

We can't inform users how a particular breach affected a particular user (based on the fact of breach alone). Anything else is just FUD. It's like saying life in California is dangerous because there were deadly hurricanes there in the past that took lives.

We can't completely control hacker attacks. We should treat them more like software bugs or service outages. It just happens, we should focus on minimizing potential damage and proper response.

Post reply on HN