HBGary isn't anywhere near the only company to have security holes like this open. It's just worse because they're a security company and they happened to piss off Anonymous. Getting employees or users not to reuse passwords is probably the hardest thing to do. Also, Ars' coverage of this story has been great.
Mammoth global corporations use passwords like 'P@55w0rd' on production systems and open servers not blocked by a firewall that store product-code and build systems. This type of 'best practice failure' occurs everywhere. For most, its like flossing every day. You know you should... but do you?
Anonymous speaks: the inside story of the HBGary hack
61–70 of 84 posts
Re: Anonymous speaks: the inside story of the HBGary hack
#62Earlier quoted context omitted.
The 'real' story is that HBGary charges that big bucks to tell other companies and/or government agencies about how they aren't following security best practices, yet they themselves weren't doing so. I don't think that anyone would be ragging on HBGary for lax security if Anonymous had pulled out some 0day kernel exploit to break into HBGary's systems. They failed in: - Keeping their systems patched and up-to-date.…
The 'real' story is that a motivated attacker will rarely fail. You can take almost any intrusion and write it up in wildly different ways. If HBGary had not failed in everything that you listed, odds are you would be listing some other comparable set of failures: - something somewhere is always unpatched and out of date - humans always deviate from best practices - 99.99% of intrusions involve traditional threats, w…
Really, you can go years without patching if you choose your software properly. (Except browsers - those just suck.)
[1] e.g. https://github.com/mojombo/jekyll [2] e.g. http://www.openbsd.org [3] e.g. http://www.openwall.com/passwdqc/ [4] http://www.openbsd.org/faq/faq14.html#RAID or the equivalent for other OSes [5] All over the internet. Or set up a Kerberos environment and get single-sign on too.
Re: Anonymous speaks: the inside story of the HBGary hack
#63Amazing write up - this is one of the best pieces of technical journalism I that I think I've seen. There is no hype, it's informed, it's detailed - but not super technical, i.e. math showing password complexity to rainbow table size tradeoffs etc. Any journalists out there, this is how it's done.
Re: Anonymous speaks: the inside story of the HBGary hack
#64Earlier quoted context omitted.
The 'real' story is that HBGary charges that big bucks to tell other companies and/or government agencies about how they aren't following security best practices, yet they themselves weren't doing so. I don't think that anyone would be ragging on HBGary for lax security if Anonymous had pulled out some 0day kernel exploit to break into HBGary's systems. They failed in: - Keeping their systems patched and up-to-date.…
The 'real' story is that a motivated attacker will rarely fail. You can take almost any intrusion and write it up in wildly different ways. If HBGary had not failed in everything that you listed, odds are you would be listing some other comparable set of failures: - something somewhere is always unpatched and out of date - humans always deviate from best practices - 99.99% of intrusions involve traditional threats, w…
As I've mentioned elsewhere, competent security needs to take into account sociological/economic analysis. Only looking at the technical and organizational side is literally just playing with yourself.
For example: if you're a major technology company, taking the step of publishing wildly popular content with DRM means you're going to be taking on a lot of highly motivated opponents. History demonstrates that this isn't a fight that you want to take on. Now consider: if you're a security company, what do you think is going to happen when you take on a subset of /b/?
Here's a hint: before you're in the position where you're risking the ire of a large, technically savvy population that's had demonstrated success taking on other corporations with comparable or greater resources than yourself and a history of flaunting the law, it really behooves you to do some preparation.
If you've been saving some chump change by keeping your mailserver on the same machine as your webserver, and you're about to take on /b/, now's the time to do something about it.
That's like some athlete not checking if his shoes are laced up properly before the event.
Did this security company ever audit its own security? Either they didn't or they did an incompetent job of that. Would you trust a security company that doesn't eat it's own cooking?
Re: Anonymous speaks: the inside story of the HBGary hack
#65Computer security is obscenely asymmetric - an attacker only has to find one flaw, once, somewhere. A defender needs to constantly monitor, test, review isolate and basically never make any mistakes. It is easy to look at almost any intrusion and attribute it to poor defenses. If HBGary didn't have a SQL injection, they'd have had a XSS vuln. Or a employee would get spearphished. Or an attacker at a local coffee shop…
When an attacker uses state of the art techniques to get through your security, you curse them and then redouble your efforts at security. When an attacker uses rudimentary techniques that have been well known for many years and have straightforward and low-cost counter-measures, then you should rightfully be disgraced. More so if you are a security company. It's not as though the attack against HBGary was like some…
Re: Anonymous speaks: the inside story of the HBGary hack
#66Earlier quoted context omitted.
> the story says hbgary hired an outside company to make this cms for them, which may explain the crappy security on that particular system. Doesn't that make them look even more amateurish and incompetent? They chose an insecure content management system and, most importantly, they didn't isolate it enough. So penetrating that resulted in a complete penetration of their site. If they were selling hand-made baskets,…
Not really, they should've tested the site themselves and there's evidence that this actually happened on the main site but not federal. Normally a company contracts an external company to do the work for them and either asks the external company to independently check the security of the output or organises it themselves. In the case of federal it may have been the case that neither happened. > If they were selling…
I've been reading through some of this HBGary stuff, and I have come to the conclusion that Aaron Barr is kinda a dipshit.
Read the email analysis at http://www.wired.com/threatlevel/2011/02/spy/ and its filled with Aaron Barr "hacking" into people's facebook accounts and then posting pictures of their kids as if he made some awesome discovery.
Re: Anonymous speaks: the inside story of the HBGary hack
#67Amazing write up - this is one of the best pieces of technical journalism I that I think I've seen. There is no hype, it's informed, it's detailed - but not super technical, i.e. math showing password complexity to rainbow table size tradeoffs etc. Any journalists out there, this is how it's done.
Re: Anonymous speaks: the inside story of the HBGary hack
#68HBGary isn't anywhere near the only company to have security holes like this open. It's just worse because they're a security company and they happened to piss off Anonymous. Getting employees or users not to reuse passwords is probably the hardest thing to do. Also, Ars' coverage of this story has been great.
It's just worse because HBGary isn't eating their own dog food. Think about that.
Re: Anonymous speaks: the inside story of the HBGary hack
#69Re: Anonymous speaks: the inside story of the HBGary hack
#70Wow. Did they do anything right? I can understand a typical organization making most of these mistakes, but a security firm?
I don't mean to shatter your dream of how security firms are run, but on the whole, I'd bet we're no better than the industry at large. This might be a "cobbler's kids shoes" issue, or just a general failure of people and process. One of the only truisms I've found so far when dealing with breaches is that almost no one gets this right proactively. You almost have to be the victim of a breach (the more public the bet…
If it's ever possible for me to hire a security firm that has higher standards than this, I'm going to do that!