Live data from Hacker News

Anonymous speaks: the inside story of the HBGary hack

arstechnica.com

51–60 of 84 posts

Re: Anonymous speaks: the inside story of the HBGary hack

#51
post #32

HBGary isn't anywhere near the only company to have security holes like this open. It's just worse because they're a security company and they happened to piss off Anonymous. Getting employees or users not to reuse passwords is probably the hardest thing to do. Also, Ars' coverage of this story has been great.

That's not a technical problem tho', it's social/organizational. If you make passwords too complex and change too often and enforce it in software, you simply encourage people to write them down, save them in the browser, etc. Or people will be phoning the helpdesk every day to get a reset, and security as a whole will be discredited as a waste of time. NOTE: I'm not saying that it is a waste of time, but the best po…

> They don't get weaker over time.

Passwords do get weaker all the time, to the extent that they are used in multiple places. Changing the password on different systems on different schedules discourages password reuse. It also means the 'active' password is much less likely to be the password the employee used on a random news site they logged into once to comment.

There is obviously a balance to be had, because frequent rotations may encourage people to choose weaker passwords, but there is certainly value in expiring passwords.

Re: Anonymous speaks: the inside story of the HBGary hack

#52
post #30

One: the root password to the machine running Greg's rootkit.com site was either "88j4bb3rw0cky88" or "88Scr3am3r88". There must be more to it than this. If you know it's one of two passwords, why bother asking - couldn't you just try both? (In retrospect, maybe it was to give Jussi confidence that he was communicating with the real Greg? [Who else, after all, would know the root passwords?])

root passwords shouldn't get you far though.

I once published all my root passwords on IRC as a challenge and didn't change them for a few weeks.

Nothing happen.

Re: Anonymous speaks: the inside story of the HBGary hack

#53
post #51
post #32

Earlier quoted context omitted.

That's not a technical problem tho', it's social/organizational. If you make passwords too complex and change too often and enforce it in software, you simply encourage people to write them down, save them in the browser, etc. Or people will be phoning the helpdesk every day to get a reset, and security as a whole will be discredited as a waste of time. NOTE: I'm not saying that it is a waste of time, but the best po…

> They don't get weaker over time. Passwords do get weaker all the time, to the extent that they are used in multiple places. Changing the password on different systems on different schedules discourages password reuse. It also means the 'active' password is much less likely to be the password the employee used on a random news site they logged into once to comment. There is obviously a balance to be had, because fre…

Changing the password on different systems on different schedules discourages password reuse.

But it doesn't, it really doesn't. It just results in people buttonholing sysadmins in the corridor asking "when are you going to stop dicking around and implement SSO?". Not long after that, people just start ignoring security advice altogether.

Re: Anonymous speaks: the inside story of the HBGary hack

#54
post #33
post #31

Earlier quoted context omitted.

Computer security is obscenely asymmetric - an attacker only has to find one flaw, once, somewhere. A defender needs to constantly monitor, test, review isolate and basically never make any mistakes. That is something the IRA used to say, they only needed to get lucky once, whereas the police needed to get lucky all the time. Of course humiliating someone on the Internet is a world away from blowing up a shopping cen…

> Incidentally there is one online group who could eat Anonymous > for breakfast - Mumsnet. If Anonymous ever took them on, they'd > be grounded before you knew it. For those less inclined, this seems like a joke as Mumsnet seems to be a UK online parenting community mostly consisting of mothers and presumably they would 'ground' Anonymous whom are supposedly just a bunch of punk kids.

Don't underestimate Mumsnet, the British government is terrified of them. Get them all pointed the same way and they are like a pack of angry she-wolves going for the wounded wildebeest of public policy. Think what they could do to any organization that doesn't have any real-world assets to protect it...

Re: Anonymous speaks: the inside story of the HBGary hack

#55
post #34
post #27

Computer security is obscenely asymmetric - an attacker only has to find one flaw, once, somewhere. A defender needs to constantly monitor, test, review isolate and basically never make any mistakes. It is easy to look at almost any intrusion and attribute it to poor defenses. If HBGary didn't have a SQL injection, they'd have had a XSS vuln. Or a employee would get spearphished. Or an attacker at a local coffee shop…

The 'real' story is that HBGary charges that big bucks to tell other companies and/or government agencies about how they aren't following security best practices, yet they themselves weren't doing so. I don't think that anyone would be ragging on HBGary for lax security if Anonymous had pulled out some 0day kernel exploit to break into HBGary's systems. They failed in: - Keeping their systems patched and up-to-date.…

The 'real' story is that a motivated attacker will rarely fail.

You can take almost any intrusion and write it up in wildly different ways.

If HBGary had not failed in everything that you listed, odds are you would be listing some other comparable set of failures:

- something somewhere is always unpatched and out of date

- humans always deviate from best practices

- 99.99% of intrusions involve traditional threats, well known vulnerabilities, unpatched systems and human error

I could write up 100 different intrusions done in 100 different ways and almost always make the victim sound incompetent, or like a real life spy novel, or make the defenses sound like fort knox, or make the intruders sound like gods, or make it sound like my product would have prevented them, or draw the conclusion that the security environment is hopeless and out of control.

In the end it doesn't really matter how it happened or what I make it sound like.

Bottom line: Did you get owned [Y/N]

Re: Anonymous speaks: the inside story of the HBGary hack

#56
post #27

Computer security is obscenely asymmetric - an attacker only has to find one flaw, once, somewhere. A defender needs to constantly monitor, test, review isolate and basically never make any mistakes. It is easy to look at almost any intrusion and attribute it to poor defenses. If HBGary didn't have a SQL injection, they'd have had a XSS vuln. Or a employee would get spearphished. Or an attacker at a local coffee shop…

Security it's not about being totally impenetrable, it's about being too expensive to be attacked.

Re: Anonymous speaks: the inside story of the HBGary hack

#57
post #28
post #12

Earlier quoted context omitted.

> the story says hbgary hired an outside company to make this cms for them, which may explain the crappy security on that particular system. Doesn't that make them look even more amateurish and incompetent? They chose an insecure content management system and, most importantly, they didn't isolate it enough. So penetrating that resulted in a complete penetration of their site. If they were selling hand-made baskets,…

Doesn't that make them look even more amateurish and incompetent? They chose an insecure content management system and, most importantly, they didn't isolate it enough. No more than google choosing a linux kernel with a privilege escalation bug for Android, anyone using OS X in 2009 while a remote jdk bug sat open for 6 months, anyone using windows+ie in dec '10 or jan '11. Unless you can explain how to only buy soft…

I understand the saying "the cobbler's children go barefoot;" if a security consulting company spent the man-hours to make sure their own systems were perfectly secure, they'd never have the spare time to bill any to their clients. Still, when making a trade-off between practicality and security, a security company should keep in mind the possible PR consequences.

This wasn't quite like Google choosing a linux kernel with a priv escalation bug or Apple leaving the JDK unpatched for 6 months. This was more like Google missing a great acquisition opportunity because they couldn't find the relevant documents on their internal fileserver, or Apple's website only rendering correctly in IE 5 because that's what they were using to test it.

Re: Anonymous speaks: the inside story of the HBGary hack

#58
post #23

SQL injection and MD5... on a "security" company? In 2011? I'm sorry but thats just egregious. Thats like being a bodyguard and not even putting a lock on your own house. The rest of the attacks could have happened to anyone. We all know its best practice to use many different passwords but most don't because its more convenient to only have one or a few. And if the email is coming from the email address it should yo…

You are completely wrong to justify people using the same passwords in multiple places because it is convenient.

Understanding a behaviour isn't the same as justifying it.

Re: Anonymous speaks: the inside story of the HBGary hack

#59

HBGary isn't anywhere near the only company to have security holes like this open. It's just worse because they're a security company and they happened to piss off Anonymous. Getting employees or users not to reuse passwords is probably the hardest thing to do. Also, Ars' coverage of this story has been great.

Company? Hell, government, military, it goes on and on how many vulnerable networks are out there.

Not in Britain, though, where there is no culture of carelessness: http://www.google.fi/search?q=british+lose+confidential+data

Re: Anonymous speaks: the inside story of the HBGary hack

#60
post #53
post #51

Earlier quoted context omitted.

> They don't get weaker over time. Passwords do get weaker all the time, to the extent that they are used in multiple places. Changing the password on different systems on different schedules discourages password reuse. It also means the 'active' password is much less likely to be the password the employee used on a random news site they logged into once to comment. There is obviously a balance to be had, because fre…

Changing the password on different systems on different schedules discourages password reuse. But it doesn't, it really doesn't. It just results in people buttonholing sysadmins in the corridor asking "when are you going to stop dicking around and implement SSO?". Not long after that, people just start ignoring security advice altogether.

You are right about reuse across multiple internal systems not being strongly discouraged.

Where it does discourage reuse is across multiple systems, and with websites. Making me change my corporate password every 90 days is an effective way to ensure that I don't use my current password across a large number of websites. Maybe I'd go to the effort of making my gmail password the same as my corporate password. The password on that random news site account I forgot about? No ways.

It's not a panacea, but password expiry does effectively limit the spread of passwords in many cases.

Post reply on HN