Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

81–90 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#81
post #74
post #69

Why build hacking tools when you can steal them? Or at least get an idea of what tools your target company was red teamed with.

Why spy on your own citizens when that makes them blackmail-able by foreign nation states? Seriously, the quickest, cheapest, easiest way to spy on someone (edit= everyone) in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part.

> Seriously, the quickest, cheapest, easiest way to spy on someone in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part.

No. The quickest and easiest way is probably to send them a phishing message, the next easiest is probably figuring some of their password recovery answers using dossiers compiled by data brokers, maybe after that it's tapping into their phone line using SS7. Probably the hardest way is to first hack a security agency, which I'd imagine have some of the better intrusion detection out there.

Re: FireEye Shares Details of Recent Cyber Attack

#82

Does a story like this negativity impact FireEye's security credibility?

It depends on how it happened, too. If it was a nation state deal and no more details come forth, I vote no. If this is a finphisher type hack and they get humiliated and db/source dumped, then yes.

Re: FireEye Shares Details of Recent Cyber Attack

#84
post #78

> FireEye CEO Mandia wrote that none of the red team tools exploited so-called “zero-day vulnerabilities,” meaning the relevant flaws should already be public. Seems like a massive amount of energy to devote to stealing tools, that by and large, probably have public equivalents sitting around on GitHub.

It is. It's equally likely that the direct goal of this attack was simply to harm FireEye.

Re: FireEye Shares Details of Recent Cyber Attack

#85
From their official blog post:

> Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities.

I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?

Re: FireEye Shares Details of Recent Cyber Attack

#86
>There is no evidence that FireEye’s hacking tools have been used or that client data was stolen

Later in same article...

>Beyond the tool theft, the hackers also appeared to be interested in a subset of FireEye customers: government agencies.

??? Which is it?

Re: FireEye Shares Details of Recent Cyber Attack

#87
post #81
post #74

Earlier quoted context omitted.

Why spy on your own citizens when that makes them blackmail-able by foreign nation states? Seriously, the quickest, cheapest, easiest way to spy on someone (edit= everyone) in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part.

> Seriously, the quickest, cheapest, easiest way to spy on someone in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part. No. The quickest and easiest way is probably to send them a phishing message, the next easiest is probably figuring some of their password recovery answers using dossiers compiled by data brokers, maybe after that…

Intercepting an sms message for 2FA is also easy nowadays via sim cloning.

Re: FireEye Shares Details of Recent Cyber Attack

#88

From their official blog post: > Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities. I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?

Probably anyone else in the Five Eyes, especially the UK.

Re: FireEye Shares Details of Recent Cyber Attack

#89
post #86

>There is no evidence that FireEye’s hacking tools have been used or that client data was stolen Later in same article... >Beyond the tool theft, the hackers also appeared to be interested in a subset of FireEye customers: government agencies. ??? Which is it?

Interest != Used or Stolen Client Data.

Re: FireEye Shares Details of Recent Cyber Attack

#90
> Consistent with a nation-state cyber-espionage effort, the attacker primarily sought information related to certain government customers.

If this was the primary objective of the attackers, why is it buried in the seventh paragraph of FireEye's blogpost, after a lengthy discussion of the attackers targeting -- though apparently not primarily targeting -- FireEye's internal tooling?

Post reply on HN