Live data from Hacker News

State of Cybersecurity Industry Exposure at Dark Web

immuniweb.com

1–10 of 28 posts

Re: State of Cybersecurity Industry Exposure at Dark Web

#3
What can I say . In general, it is not entirely clear which part of the dark web is meant https://utopia.fans/networks/dark-web-vs-deep-web-what-is-ea... and what could be safe there? No matter how you look, it is nevertheless an undetected part of the Internet, and for the most part there are all sorts of illegal things.

Re: State of Cybersecurity Industry Exposure at Dark Web

#4

"97% of companies have data leaks and other security incidents exposed on the Dark Web" - Bold claims. Do you have any proof of this? Such as redacted screenshots or examples of these leaks? The article shows lots of stats, but no real evidence.

There are some people that say, now I am not saying it, but there are people that say, “Your data is on the Dark Web”.

It looks like FUD, it sounds like FUD, then in my books, it is FUD. Fortunately it is easy to get out of infosec meetings that blather on with these generic statements while working from home. No awkward walking out of the room.

Re: State of Cybersecurity Industry Exposure at Dark Web

#5

"97% of companies have data leaks and other security incidents exposed on the Dark Web" - Bold claims. Do you have any proof of this? Such as redacted screenshots or examples of these leaks? The article shows lots of stats, but no real evidence.

replace Dark Web with NSA, and I'll probably buy it. Other than that. It sounds like FUD.

Re: State of Cybersecurity Industry Exposure at Dark Web

#6
There are so many "numbers" reports in the cybersecurity industry without any kind of way for validating the claims that I think all of them have equal value - close to zero.

The only source of truth in this industry is speaking with the "frontline" and figuring out how things really are.

Re: State of Cybersecurity Industry Exposure at Dark Web

#7
While the evidence is light. Is anyone surprised if this is true? My experience is that most cybersecurity firms are only slightly better than other enterprises. They often have lofty standards that they themselves don't follow.

They also have professional service arms that are similar to the rest of the industry. Handful of senior people and an army of junior engineers that bias towards velocity over quality (i.e. take shortcuts that can lead to data exposure and other issues)

Re: State of Cybersecurity Industry Exposure at Dark Web

#8
It comes up with 130 high risk events for ycombinator.com [0](accounts with plain text passwords) and 294 medium risk events (accounts with encrypted passwords)

This feels like the sum of all the domain accounts from leaked breaches - similar to have I been pwned

Despite what the report says - you can't actually verify the data without signing up to their service and doing the whole sales funnel thing

[0] https://www.immuniweb.com/radar/?id=kKhvrIhe

Re: State of Cybersecurity Industry Exposure at Dark Web

#9

"97% of companies have data leaks and other security incidents exposed on the Dark Web" - Bold claims. Do you have any proof of this? Such as redacted screenshots or examples of these leaks? The article shows lots of stats, but no real evidence.

It looks like it’s based on looking for the companies’ domains in password and data dumps, in which case 97% is utterly unsurprising and I bet the 3% are just too new to have had any users in a major breach.

Re: State of Cybersecurity Industry Exposure at Dark Web

#10
post #9

"97% of companies have data leaks and other security incidents exposed on the Dark Web" - Bold claims. Do you have any proof of this? Such as redacted screenshots or examples of these leaks? The article shows lots of stats, but no real evidence.

It looks like it’s based on looking for the companies’ domains in password and data dumps, in which case 97% is utterly unsurprising and I bet the 3% are just too new to have had any users in a major breach.

How exactly does that work though?

I'm not connived that every name in a data dump indicates a breach at a given company.

My thinking:

If someone gets a hold of a huge list of usersnaems and passwords from bobcompany.com, and then spams numerous sites with those logins to see if they work elsewhere ... and finds that a few work on joecompany.com then puts out that data.... joecompany.com might have their name listed somewhere in someone's data dump, but they didn't have a breach...

Post reply on HN