Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

201–210 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#201
post #76
post #65

Earlier quoted context omitted.

1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies [1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-rele…

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

They took it down. What did it say?

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#202
post #95
post #76

Earlier quoted context omitted.

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

“Resecurity Inc., California-Based cybersecurity company” timezone_string: Europe/Kiev Admin IP address: 109.207.124.196, AS196740, Ukraine Really piling on the confidence here.

I just did a search for `"resecurity" kiev ukraine` on Google and got some strange results showing news articles from well-known sites stating KIEV, UKRAINE in context with the article's top pic... I'm not sure how to explain that:

Why The Citrix Breach Matters -- And What To Do Next Forbes "resecurity" kiev ukraine from www.forbes.com 18 hours ago · KIEV, UKRAINE - 2019/01/20: Citrix Systems Software company logo seen ... According to security firm Resecurity, the attacks were perpetrated by ...

https://www.google.com/amp/s/www.forbes.com/sites/kateoflahe...

https://www.forbes.com/sites/kateoflahertyuk/2019/03/10/citr...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#203
post #95
post #76

Earlier quoted context omitted.

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

“Resecurity Inc., California-Based cybersecurity company” timezone_string: Europe/Kiev Admin IP address: 109.207.124.196, AS196740, Ukraine Really piling on the confidence here.

This one's before the Forbes article:

Citrix Data Breach – Next is what to do next newsbeezer.com "resecurity" kiev ukraine from newsbeezer.com 19 hours ago · KIEV, UKRAINE – 2019/01/ 20: Citrix Systems software ... According to Security Company Resecurity, the attacks were ...

https://newsbeezer.com/zimbabwe/citrix-data-breach-next-is-w...

Here's the article's top image sub-text:

Citrix was hit by hackers in attacks that may have exposed large amounts of customer data. KIEV, UKRAINE – 2019/01/20: Citrix Systems software Company logo displayed on a smartphone. (Photo by Igor Golovniov / SOPA Images / LightRocket on Getty Images) Getty

The image is hosted by Forbes: https://thumbor.forbes.com/thumbor/600x315/https%3A%2F%2Fspe...

Why newsbreezer has an article dated an hour earlier in a Google search than the Forbes article which is hosting the image on both sites, and why it's coincidentally sub-texted with KIEV, UKRAINE, I can't explain...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#204
post #3

Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…

"Compromise feels almost inevitable ... I wouldn't put personal data I am not willing to lose online"

I kinda wonder. How do you do that in our modern age? Is the computer you store the data on connected to the internet? If the answer is yes, your data can be accessed. If the answer is no, is that computer on the same network as any other device you use to connect to the internet? If the answer is yes, your data can be accessed. If the answer is no, you might be secure, but then I have a question, who the hell are you that you run a disconnected, private network just to store some personal data?

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#205
post #199
post #197

Earlier quoted context omitted.

If you place the ID after the ballot is handed out (by a printer that is also used to fill in the ballot). Then this systems still doesn't allow proving of votes. The ID here is meant to identify a ballot, not a voter. It should probably be something like a UUID. The aim of this system is to allow cross-checking between the scanner and the physical ballots.

> The ID here is meant to [..] I got that, but you can still kind of prove it. Your know your ID + your-vote. This is likely the only valid ID+vote combination you can know before results are counted. That's when I'd "ask" you and late verify it. If you want to verify the machine is working, just put the ballot in the standard bin and add those IDs in the counting phase. That seems fine in principle and make it easy…

> add those IDs in the counting phase

That'd probably work. You'd need to somehow ensure the scanner that ads the IDs doesn't double IDs

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#206

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Looks like the Iran connection came from a guy with a history of opportunistically jumping in on big security news stories: https://mobile.twitter.com/imdeaconblues/status/110504680622...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#207

Earlier quoted context omitted.

I think the idea is more about informing users than it is about trying to drum up a boycott that results in a "death sentence". For example, with regards to search engines, what if I go on Google and it tells me "hey, Google has had 3 data breaches that have effected users like you". And then I go on DuckDuckGo and it says "DDG has never had a data breach". Not everyone will switch from Google to DDG, but some people…

We can't inform users how a particular breach affected a particular user (based on the fact of breach alone). Anything else is just FUD. It's like saying life in California is dangerous because there were deadly hurricanes there in the past that took lives. We can't completely control hacker attacks. We should treat them more like software bugs or service outages. It just happens, we should focus on minimizing potent…

> It's like saying life in California is dangerous because there were deadly hurricanes there in the past that took lives.

I'm not sure this is the analogy you are looking for. If you are concerned with how a hurricane might impact your livelihood, it's generally a much better idea to live in Colorado than on the coast of California.

Except unlike hurricanes, we absolutely can prevent hacks that leak a lot of user information.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#208
post #177
post #76

Earlier quoted context omitted.

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

This url is now showing a 404.

https://archive.is/https://resecurity.com/wp-content/uploads...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#209
post #76

Earlier quoted context omitted.

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

They took it down. What did it say?

It was an SQL dump of their entire database: https://archive.is/https://resecurity.com/wp-content/uploads...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#210
post #76

Earlier quoted context omitted.

https://resecurity.com/wp-content/uploads/2018/05/wp_res2.sq... seriously?

Is there any risk you take by posting that? That is a page that I doubt the author would have wanted to be public, and is not linked to from the home page or its descendants. Wasn't that the case against weev? (IMO, if it is public, it should be legal to post to it, but whatever.)

It was linked from https://resecurity.com/wp-content/uploads/, which is a common and public URL, and anything uploaded there is intended to be public. Of course, whoever uploaded it either wasn't aware or didn't think it through--maybe they thought nobody would ever visit that page.

As you can see, the link is gone now.

Post reply on HN