Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

51–60 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#51
post #35
post #18

Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.

I mean, FireEye has a pretty good reputation for attribution and investigation of nation state intrusions. This doesn't seem like the type of thing they would just make up. Bot saying we should take them 100% at their word, but investigating intrusions is their entire reason for existence

They have a reputation for making up salacious stories based on totally inconclusive, inadequate "evidence". No wonder they turned it up to 11 when it was themselves getting breached.

Re: FireEye Shares Details of Recent Cyber Attack

#52
post #42
post #11

Earlier quoted context omitted.

Maybe you should try to gain a basic understanding of what you're talking about before posting this /pol/ conspiracy theory stuff? There exists very little doubt that NK was behind the Sony hack, there's even a federal indictment. >It is the same as Crowdstrike going back on their wild claims while their CEO testified under oath. This is a complete fabrication by you, utterly unsupported by the link you shared which…

Here is the congressional sworn testimony of Shawn Henry, the CEO of Crowdstrike, specifically saying that there is no concrete evidence of Russian hacking of the DNC. https://intelligence.house.gov/uploadedfiles/sh21.pdf You can peruse the whole pdf or jump straight to the money quote on page 32. As for federal indictment on North Korea, that means nothing on the merits or dubiousness of the North Koreans hacking So…

>Here is the congressional sworn testimony of Shawn Henry, the CEO of Crowdstrike, specifically saying that there is no concrete evidence of Russian hacking of the DNC.

It feels like you're being deliberately dishonest. Your "money quote" is about whether there were was concrete evidence of the hackers exfiltrating data from the DNC, not about "Russian hacking of the DNC" .

What Shawn Henry is saying there is that they have evidence of the hackers preparing data for exfiltration, but no concrete evidence of the data being transferred out. Unless the malware used by the hackers stores detailed logs, this is to be expected. It would be unreasonable to doubt that the exfiltration happened on this basis.

>In fact, there was a smoking gun to a disgruntled ex employee

There wasn't. None of your links substantiate this claim.

The wikipedia section consists of uninformed clowns like Sabu and hilarious quotes like "State-sponsored attackers don't create cool names for themselves like 'Guardians of Peace' and promote their activity to the public.". There's no genuine attempt at convincing criticism of the NK attribution to be found here.

>As for federal indictment on North Korea, that means nothing on the merits or dubiousness of the North Koreans hacking Sony

The federal government has a pretty good track record of getting these things right. The DOJ certainly believes that NK did the Sony hack.

Re: FireEye Shares Details of Recent Cyber Attack

#53

I found an XSS on FireEye's website when I was a pentester. Good times.. It took all night, too. Was worried it'd be the first gig I wasn't able to get a medium severity on. I'm not sure anything can protect against a targeted attack from a nation-state. It's tempting to think that you can. But the warfare is asymmetric; they have all the time in the world to become certain that they can breach your outer defenses. O…

>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way

Honestly, system user education/awareness goes even further. Iran nuclear facilities used an airgap but it was social engineering that was the weakest attack vector for Stuxnet to exploit. Same with the South Korean Winter Olympics; a phishing email with a macro embedded Word doc got them in there.

A great book on Russian, state-backed hacking group was by a senior Wired writer, Andy Greenberg, called "Sandworm" [0]

[0] https://www.amazon.com/Sandworm-Cyberwar-Kremlins-Dangerous-...

Re: FireEye Shares Details of Recent Cyber Attack

#54

> During our investigation to date, we have found that the attacker targeted and accessed did their best to bury the lede. they say they were targeted multiple times, but dont say they were breached until the fourth paragraph, something like 40% of the way through - even then the admission is intentionally mentioned vice announced. i understand fireeye is a security company, but pussyfooting is pussyfooting and wease…

As someone who has done some work in the PR sector, it was established that it's crucial to ensure the correct narrative is delivered.

There can be times when the "factually accurate" narrative conflicts with the correct one, there's a reason why most corporations have dedicated resources for engaging with the public.

What one normally consider to be "weasel words" are often carefully chosen to polish the truth while alleviating harm to key stakeholders.

Re: FireEye Shares Details of Recent Cyber Attack

#55
post #38
post #36

Earlier quoted context omitted.

They are seeking attention by saying they got hacked, when their entire reason for existence is to defend networks?

It reads like a brochure written by a marketing department, "top-tier offensive capabilities... world-class... operated clandestinely... They used a novel combination of techniques not witnessed by us or our partners in the past... nation-state cyber-espionage". It's way over-the-top.

Of course it was written by a marketing department. They're a $3B public company with 3,400 employees. And you're proposing they faked a security breach and lied to the FBI so they could get media attention? Please be joking.

Re: FireEye Shares Details of Recent Cyber Attack

#56
post #41

This demonstrates two major points that many people not familiar with security may not understand: The first is that anyone -- really, anyone -- can get hacked. I often joke with our CIO that security would be a lot easier if he just powered down our production infrastructure. Security is a game played in layers (often called "defense in depth"), but at the end of the day, it's almost impossible to prevent a breach w…

You missed the third major point that most people do not know which is that these attacks are not just possible, they are easy. Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. That is unequivocal garbage. I have never had a CISO (or any other high-level securi…

>Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack.

While this is true for e.g., Equifax (see https://ciexinc.com/blog/quick-assessment-of-a-companys-secu...), if FireEye (aka Mandiant) says it, I tend to believe it to be quite true.

I would expect that hacking them would be far from easy.

Re: FireEye Shares Details of Recent Cyber Attack

#57
post #10

The problem with these articles is the cloak and dagger nature of these stories and the lack of healthy skepticism. While not necessarily the case here, every big tech company puts blame on an APT aka a nation state actor. In fact, the very same FireEye attributed the Sony Pictures hack to North Korea on extremely flimsy grounds. By those same measures one could have implicated East Palo Alto High School. You never r…

I have respect for Kim Zetter, but in a hard-core discussion about who hacked Sony, I'm going to tend more to believe FireEye.

> ... FireEye attributed the Sony Pictures hack to North Korea on extremely flimsy grounds.

What grounds are flimsy that they used? Do you have details about what FireEye actually saw?

Re: FireEye Shares Details of Recent Cyber Attack

#58
post #38

Earlier quoted context omitted.

It reads like a brochure written by a marketing department, "top-tier offensive capabilities... world-class... operated clandestinely... They used a novel combination of techniques not witnessed by us or our partners in the past... nation-state cyber-espionage". It's way over-the-top.

Of course it was written by a marketing department. They're a $3B public company with 3,400 employees. And you're proposing they faked a security breach and lied to the FBI so they could get media attention? Please be joking.

[deleted]

Re: FireEye Shares Details of Recent Cyber Attack

#60

I found an XSS on FireEye's website when I was a pentester. Good times.. It took all night, too. Was worried it'd be the first gig I wasn't able to get a medium severity on. I'm not sure anything can protect against a targeted attack from a nation-state. It's tempting to think that you can. But the warfare is asymmetric; they have all the time in the world to become certain that they can breach your outer defenses. O…

>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way

How do you get updates to your airgapped hardware? That's your attack vector.
Post reply on HN