Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.
I mean, FireEye has a pretty good reputation for attribution and investigation of nation state intrusions. This doesn't seem like the type of thing they would just make up. Bot saying we should take them 100% at their word, but investigating intrusions is their entire reason for existence
FireEye Shares Details of Recent Cyber Attack
51–60 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#52Earlier quoted context omitted.
Maybe you should try to gain a basic understanding of what you're talking about before posting this /pol/ conspiracy theory stuff? There exists very little doubt that NK was behind the Sony hack, there's even a federal indictment. >It is the same as Crowdstrike going back on their wild claims while their CEO testified under oath. This is a complete fabrication by you, utterly unsupported by the link you shared which…
Here is the congressional sworn testimony of Shawn Henry, the CEO of Crowdstrike, specifically saying that there is no concrete evidence of Russian hacking of the DNC. https://intelligence.house.gov/uploadedfiles/sh21.pdf You can peruse the whole pdf or jump straight to the money quote on page 32. As for federal indictment on North Korea, that means nothing on the merits or dubiousness of the North Koreans hacking So…
It feels like you're being deliberately dishonest. Your "money quote" is about whether there were was concrete evidence of the hackers exfiltrating data from the DNC, not about "Russian hacking of the DNC" .
What Shawn Henry is saying there is that they have evidence of the hackers preparing data for exfiltration, but no concrete evidence of the data being transferred out. Unless the malware used by the hackers stores detailed logs, this is to be expected. It would be unreasonable to doubt that the exfiltration happened on this basis.
>In fact, there was a smoking gun to a disgruntled ex employee
There wasn't. None of your links substantiate this claim.
The wikipedia section consists of uninformed clowns like Sabu and hilarious quotes like "State-sponsored attackers don't create cool names for themselves like 'Guardians of Peace' and promote their activity to the public.". There's no genuine attempt at convincing criticism of the NK attribution to be found here.
>As for federal indictment on North Korea, that means nothing on the merits or dubiousness of the North Koreans hacking Sony
The federal government has a pretty good track record of getting these things right. The DOJ certainly believes that NK did the Sony hack.
Re: FireEye Shares Details of Recent Cyber Attack
#53I found an XSS on FireEye's website when I was a pentester. Good times.. It took all night, too. Was worried it'd be the first gig I wasn't able to get a medium severity on. I'm not sure anything can protect against a targeted attack from a nation-state. It's tempting to think that you can. But the warfare is asymmetric; they have all the time in the world to become certain that they can breach your outer defenses. O…
>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way
A great book on Russian, state-backed hacking group was by a senior Wired writer, Andy Greenberg, called "Sandworm" [0]
[0] https://www.amazon.com/Sandworm-Cyberwar-Kremlins-Dangerous-...
Re: FireEye Shares Details of Recent Cyber Attack
#54> During our investigation to date, we have found that the attacker targeted and accessed did their best to bury the lede. they say they were targeted multiple times, but dont say they were breached until the fourth paragraph, something like 40% of the way through - even then the admission is intentionally mentioned vice announced. i understand fireeye is a security company, but pussyfooting is pussyfooting and wease…
There can be times when the "factually accurate" narrative conflicts with the correct one, there's a reason why most corporations have dedicated resources for engaging with the public.
What one normally consider to be "weasel words" are often carefully chosen to polish the truth while alleviating harm to key stakeholders.
Re: FireEye Shares Details of Recent Cyber Attack
#55Earlier quoted context omitted.
They are seeking attention by saying they got hacked, when their entire reason for existence is to defend networks?
It reads like a brochure written by a marketing department, "top-tier offensive capabilities... world-class... operated clandestinely... They used a novel combination of techniques not witnessed by us or our partners in the past... nation-state cyber-espionage". It's way over-the-top.
Re: FireEye Shares Details of Recent Cyber Attack
#56This demonstrates two major points that many people not familiar with security may not understand: The first is that anyone -- really, anyone -- can get hacked. I often joke with our CIO that security would be a lot easier if he just powered down our production infrastructure. Security is a game played in layers (often called "defense in depth"), but at the end of the day, it's almost impossible to prevent a breach w…
You missed the third major point that most people do not know which is that these attacks are not just possible, they are easy. Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. That is unequivocal garbage. I have never had a CISO (or any other high-level securi…
While this is true for e.g., Equifax (see https://ciexinc.com/blog/quick-assessment-of-a-companys-secu...), if FireEye (aka Mandiant) says it, I tend to believe it to be quite true.
I would expect that hacking them would be far from easy.
Re: FireEye Shares Details of Recent Cyber Attack
#57The problem with these articles is the cloak and dagger nature of these stories and the lack of healthy skepticism. While not necessarily the case here, every big tech company puts blame on an APT aka a nation state actor. In fact, the very same FireEye attributed the Sony Pictures hack to North Korea on extremely flimsy grounds. By those same measures one could have implicated East Palo Alto High School. You never r…
> ... FireEye attributed the Sony Pictures hack to North Korea on extremely flimsy grounds.
What grounds are flimsy that they used? Do you have details about what FireEye actually saw?
Re: FireEye Shares Details of Recent Cyber Attack
#58Earlier quoted context omitted.
It reads like a brochure written by a marketing department, "top-tier offensive capabilities... world-class... operated clandestinely... They used a novel combination of techniques not witnessed by us or our partners in the past... nation-state cyber-espionage". It's way over-the-top.
Of course it was written by a marketing department. They're a $3B public company with 3,400 employees. And you're proposing they faked a security breach and lied to the FBI so they could get media attention? Please be joking.
Re: FireEye Shares Details of Recent Cyber Attack
#59Re: FireEye Shares Details of Recent Cyber Attack
#60I found an XSS on FireEye's website when I was a pentester. Good times.. It took all night, too. Was worried it'd be the first gig I wasn't able to get a medium severity on. I'm not sure anything can protect against a targeted attack from a nation-state. It's tempting to think that you can. But the warfare is asymmetric; they have all the time in the world to become certain that they can breach your outer defenses. O…
>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way