Earlier quoted context omitted.
You missed the third major point that most people do not know which is that these attacks are not just possible, they are easy. Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. That is unequivocal garbage. I have never had a CISO (or any other high-level securi…
>Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. While this is true for e.g., Equifax (see https://ciexinc.com/blog/quick-assessment-of-a-companys-secu... ), if FireEye (aka Mandiant) says it, I tend to believe it to be quite true. I would expect that hacking…
FireEye Shares Details of Recent Cyber Attack
61–70 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#62Earlier quoted context omitted.
>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way
Airgaps protect against low to medium level attackers. Nation state tools for bypassing airgaps are a dime a dozen. One of the most common is interdiction of computers in shipping and installation of hardware implants.
Re: FireEye Shares Details of Recent Cyber Attack
#63Earlier quoted context omitted.
You missed the third major point that most people do not know which is that these attacks are not just possible, they are easy. Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. That is unequivocal garbage. I have never had a CISO (or any other high-level securi…
>Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. While this is true for e.g., Equifax (see https://ciexinc.com/blog/quick-assessment-of-a-companys-secu... ), if FireEye (aka Mandiant) says it, I tend to believe it to be quite true. I would expect that hacking…
Second, that is kind of a non-sequitur. I did not say that a nation-state did not pull off the attack, my gripe is that they are implying, like every other company that gets breached, that only a nation-state has the resources to pull off such an attack with their wording. These attacks are extremely cheap and easy, that is why we see governments running literally hundreds to thousands of such attacks/programs in parallel as evidenced by the CIA Vault 7 leaks. A single branch of the US government was literally developing hundreds of independent tools/programs that could successfully compromise anything they cared to target.
Third, define "easy". I define easy as ~$1,000,000-$10,000,000 since almost any moderately-sized corporation, of which there are millions, could fund such an operation. To put it in perspective, $10,000,000 is only ~1% of FireEye's revenue. I define "only a nation-state" at 1,000x more at ~$1,000,000,000-~$10,000,000,000 since although it is still technically doable for a large multinational or organized crime, it is unlikely to be profitable outside of theoretical large-scale extortion attacks.
Do you think a penetration test of 3 engineers working fulltime for a year would fail to materially breach FireEye's corporate systems? Almost every penetration test by a competent company takes a fraction of that effort even against well-funded security teams. And 3 engineers for one year is only 3 engineer-years which at $300k/engineer-year is ~$1,000,000, the bottom end of "easy" and 1,000x less than "only nation-states can pull it off". If engineer-years is too abstract, the Google ProjectZero case I mentioned earlier was a zero-click iOS RCE from zero starting understanding in 0.5 engineer-years. So, doing some sloppy extrapolation, is it easier to find 6 zero-click iOS RCEs or breach FireEye's corporate systems?
Let's say we moved up an order of magnitude to 1% of FireEye's revenue at $10,000,000 which is the high end of "easy" and is 2 orders of magnitude less than the bottom end of "only nation-states can pull it off". That would be enough to fund 30 engineers working fulltime for a year or 10 engineers working fulltime for 3 years. Do you think FireEye could prevent a material breach? I have literally never heard of a single person in enterprise security who has ever dared to make such a remark on the record that was not instantly taken down for a fraction of that. I know of no competent engineers in that space who would support making such a statement to anybody who could and would test it. Just think if FireEye announced a $10,000,000 prize at DefCon to breach their systems by the end of the year, do you think they would even last the month?
[1] http://www.cnmeonline.com/myresources/fireeye/fireeye-cso-le...
[2] https://web.archive.org/web/20120610031926/https://www.firee...
Re: FireEye Shares Details of Recent Cyber Attack
#64> During our investigation to date, we have found that the attacker targeted and accessed did their best to bury the lede. they say they were targeted multiple times, but dont say they were breached until the fourth paragraph, something like 40% of the way through - even then the admission is intentionally mentioned vice announced. i understand fireeye is a security company, but pussyfooting is pussyfooting and wease…
Re: FireEye Shares Details of Recent Cyber Attack
#65Re: FireEye Shares Details of Recent Cyber Attack
#66Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.
So, what do we all think would be a level of resources that only a state could support? I think we can just start somewhere pretty low like $1,000,000,000. Fortune 500 companies and many criminal organizations could reasonably afford that, but the total number of organizations is still pretty limited, so it is probably a good lower bound. I do not think we can go much lower because if we drop down to $100,000,000 then even FireEye, which is not a Fortune 500 company, could theoretically fund such a venture with its revenue of $890,000,000.
Okay, so starting with "only a state" resource level of $1,000,000,000, we should probably divide it by 10 to make it highly unlikely people will do it just to prove they can even if it is unprofitable to get the prize. That leaves us with a simple open prize of $100,000,000 for the first person to demonstrate that they can breach their systems. If nobody claims the prize, then it is highly likely that this attack would take a state-level actor. If somebody does claim the prize, then it is probably doable by somebody who is not a state-level actor. This would provide an unbiased answer about the truth of their implications. If they think such a prize is too high, then they can just set it to a lower X that will give us an unbiased answer to the question: "Does it take more than X resources to breach their systems?"
Re: FireEye Shares Details of Recent Cyber Attack
#67Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.
Well they could pretty easily demonstrate that only a state actor could pull off an attack like this in an objective manner. If it takes state-level resources to breach their systems, then they can just announce and put out an open prize for anybody who can breach their systems that pays out less than state-level resources. If it actually takes state-level resources to breach their systems, but pays out less than tha…
Re: FireEye Shares Details of Recent Cyber Attack
#68Re: FireEye Shares Details of Recent Cyber Attack
#69Or at least get an idea of what tools your target company was red teamed with.