Anonymous speaks: the inside story of the HBGary hack
arstechnica.com
Anonymous speaks: the inside story of the HBGary hack
1–10 of 84 posts
Re: Anonymous speaks: the inside story of the HBGary hack
#2Getting employees or users not to reuse passwords is probably the hardest thing to do.
Also, Ars' coverage of this story has been great.
Re: Anonymous speaks: the inside story of the HBGary hack
#3I can understand a typical organization making most of these mistakes, but a security firm?
Re: Anonymous speaks: the inside story of the HBGary hack
#4HBGary isn't anywhere near the only company to have security holes like this open. It's just worse because they're a security company and they happened to piss off Anonymous. Getting employees or users not to reuse passwords is probably the hardest thing to do. Also, Ars' coverage of this story has been great.
For most, its like flossing every day. You know you should... but do you?
Re: Anonymous speaks: the inside story of the HBGary hack
#5Re: Anonymous speaks: the inside story of the HBGary hack
#6"Even with the flawed usage of MD5, HBGary could have been safe..."
They homebrewed their own password system. Can someone switch on the tptacek bat-signal?
Re: Anonymous speaks: the inside story of the HBGary hack
#7Very well written article - it does a terrific job of explaining things like rainbow tables for a non-technical (or at least, technically-but-not-security-minded) audience. The only part that seems off is the theme that /all/ of the exploited vulnerabilities were necessary to render HBGary vulnerable: "Even with the flawed usage of MD5, HBGary could have been safe..." They homebrewed their own password system. Can so…
the story says hbgary hired an outside company to make this cms for them, which may explain the crappy security on that particular system.
Can someone switch on the tptacek bat-signal?
thomas' security company also got hacked a couple years ago and had sensitive information plastered all over a mailing list. rumor was that it happened via their use of wordpress for their weblog.
i guess the moral of the story is... you will get hacked by crappy third-party software?
Re: Anonymous speaks: the inside story of the HBGary hack
#8Re: Anonymous speaks: the inside story of the HBGary hack
#9HBGary isn't anywhere near the only company to have security holes like this open. It's just worse because they're a security company and they happened to piss off Anonymous. Getting employees or users not to reuse passwords is probably the hardest thing to do. Also, Ars' coverage of this story has been great.
Re: Anonymous speaks: the inside story of the HBGary hack
#10HBGary isn't anywhere near the only company to have security holes like this open. It's just worse because they're a security company and they happened to piss off Anonymous. Getting employees or users not to reuse passwords is probably the hardest thing to do. Also, Ars' coverage of this story has been great.
One point in favor of requiring ssh keys for external access is that the users don't get to blow it on passwords. Though it does require sysadmin staff who are willing to walk users through the process of creating the keys --- and stubborn enough to explain that this is the procedure until following it becomes the path of least resistance.