Live data from Hacker News

Hackers went undetected in Citrix’s internal network for six months

techcrunch.com

21–30 of 122 posts

Re: Hackers went undetected in Citrix’s internal network for six months

#21
post #18

Having worked with Citrix, I'm shocked. Shocked that they detected it at all...

I was going to say the same thing, but it sounds like it was the FBI that noticed it: > [T]he hackers had “intermittent access” to its internal network from October 13, 2018 until March 8, 2019, two days after the FBI alerted the company to the breach.

Oh, this is gold, thank you. I'm sorry I missed it, but at least answers my very serious skepticism.

Re: Hackers went undetected in Citrix’s internal network for six months

#22
post #5

average is 206 days

According to whom? That's significantly above what fireeye says (71 until internally discovered): https://content.fireeye.com/m-trends

According to Google search snippet I am totally ready to trust that FireEye estimate is much more accurate

Re: Hackers went undetected in Citrix’s internal network for six months

#23
post #2

Security is hard. On the upside, every breach is a chance to learn for everyone else. I hope they release more details on how it happened. Is there any blog or news that summarizes such post-mortem lessons? Could be a nice project to collect that.

There's always https://catless.ncl.ac.uk/Risks/

Subscribed. Also found https://securereading.com/category/news/latest-hacks/

Re: Hackers went undetected in Citrix’s internal network for six months

#24

> Citrix said in a later update on April 4 that the attack was likely a result of password spraying, which attackers use to breach accounts by brute-forcing from a list of commonly used passwords that aren’t protected with two-factor authentication. How did Citrix not have 2FA in place?

It's Citrix. That's how.

Re: Hackers went undetected in Citrix’s internal network for six months

#25
post #21

Earlier quoted context omitted.

I was going to say the same thing, but it sounds like it was the FBI that noticed it: > [T]he hackers had “intermittent access” to its internal network from October 13, 2018 until March 8, 2019, two days after the FBI alerted the company to the breach.

Oh, this is gold, thank you. I'm sorry I missed it, but at least answers my very serious skepticism.

Believe me, your skepticism in this matter is not unique!

Re: Hackers went undetected in Citrix’s internal network for six months

#26
post #18

Having worked with Citrix, I'm shocked. Shocked that they detected it at all...

I was going to say the same thing, but it sounds like it was the FBI that noticed it: > [T]he hackers had “intermittent access” to its internal network from October 13, 2018 until March 8, 2019, two days after the FBI alerted the company to the breach.

This is extremely common. 6 months is not that long, even among competent companies that have good security. You usually hear about it from the FBI. I think the FBI forwards tips from agencies like the NSA, but they don’t tend to give much information.

Re: Hackers went undetected in Citrix’s internal network for six months

#27

Earlier quoted context omitted.

Just assume they only catch the dumbest 20%.

So you think that 80% of attacks are better than stuxnet?

They never caught the stuxnet attacks. They caught the malware that was spreading far outside of its target. Not quite the same thing.

Re: Hackers went undetected in Citrix’s internal network for six months

#28
post #6

I fully assume there are more hacks we don’t hear about that ones we do. Not only because of cover ups but it can’t be that hard to cover your tracks if you know what you are doing.

Its an interesting question. If someone unauthorized was on your network exfiltrating data how would you know?

Re: Hackers went undetected in Citrix’s internal network for six months

#29
post #15

Earlier quoted context omitted.

Probably my wording was wrong. I was thinking more of a system where the password itself was generated and stored on a hardware device. The user need not interact with any application, whatsoever, like 1Password or Lastpass to generate or store a password at all. Everything happens behind the scenes on the device. The user would be responsible only for keeping the hardware device safe. This probably makes 2FA moot fo…

I understood you, my point is that you are sacrificing significant security with a one-factor approach, especially if that one factor is a password! You're open to attacks where the password is exposed in between the keyboard and the requestor, attacks on the distant end system, as well as attacks on the password device itself. Passwords make it tricky to audit if they've been duplicated. Use 2fa everywhere. It's che…

I do not believe that spearphishing would not be prevented by a hardware token. The device would be responsible for authenticating the identity of the service being accessed. If the user can be fooled into handing over their hardware token, I do not see it far fetched that they will not be influenced to not hand over their 2FA token.

Again, if a hardware 2FA token can deal with key-loggers, so can a password token.

Why would someone be able to shoulder-surf a display-less password token? You log on to the website, insert the device and the website proceeds to authentication without revealing anything.

Evil maid is the only legitimate attack I can agree with.

>attacks on the distant end system, as well as attacks on the password device itself.

This is not something that a hardware 2FA token is also foolproof against.

>Passwords make it tricky to audit if they've been duplicated.

This is a valid point.

My point may not be applicable for super sensitive systems but for a lot of services it should be sufficient enough. I'm saying so because I'm having a hard time getting my family/friends to use a password manager (specifically 1Password). They do not see the need, find it additionally complex and are turned off by the subscription pricing (I'm paying for my family though!). Syncing is also hard. I was hoping that a pure hardware token would make it more convenient and a one time 20-40 USD price is more palatable than 60 USD every year.

Re: Hackers went undetected in Citrix’s internal network for six months

#30
post #29

Earlier quoted context omitted.

I understood you, my point is that you are sacrificing significant security with a one-factor approach, especially if that one factor is a password! You're open to attacks where the password is exposed in between the keyboard and the requestor, attacks on the distant end system, as well as attacks on the password device itself. Passwords make it tricky to audit if they've been duplicated. Use 2fa everywhere. It's che…

I do not believe that spearphishing would not be prevented by a hardware token. The device would be responsible for authenticating the identity of the service being accessed. If the user can be fooled into handing over their hardware token, I do not see it far fetched that they will not be influenced to not hand over their 2FA token. Again, if a hardware 2FA token can deal with key-loggers, so can a password token. W…

[deleted]
Post reply on HN