Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

171–180 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#171

Earlier quoted context omitted.

But nothing is known, we have to believe a company trying to master a PR shitshow right now, saying that the attackers were extremely sophisticated. Maybe it was, maybe they are "inflating" the sophistication of the attack to avoid looking bad. Besides that, I care little about "attribution specialists" and what they say (sorry if anybody is in the audience :p). Evidence can be faked, it's all bits and bytes in the e…

The FBI has confirmed the state-level adversary thing in a release today. There is no love lost between the outgoing administration and FireEye. You're probably never going to get evidence that will satisfy a message board. The Wikileaks post you cited repeats the fallacy I mentioned earlier --- the idea that analysts are simply attributing exploit code. I think if you stop and think about it, you can probably rattle…

No, I am not saying a bored teenager can create evidence like that, but the sophisticated nation states surely can, and probably some other larger orgs, too.

Code can be faked, meta data can be faked, MO can be imitated, and so on. And the nation states at the very least - and their contractors and (former) employees in the areas of concern - will know what it has to look like. Motive isn't always clear, and quite often there are multiple parties with motives.

>unless you've had some real exposure to IR and forensics as a practitioner.

I'll bite on your argumentum ad verecundiam... who says I didn't? ;)

But I agree, we'll likely never see evidence or a post mortem, and are expected to believe what FireEye and/or the FBI tells us.

Re: FireEye Shares Details of Recent Cyber Attack

#172
post #92

Earlier quoted context omitted.

Indeed. It would, however, provide very strong evidence for most such claims. The primary problem with actually implementing it in general is the risk of getting unlucky if you have a very large payout. Say you claim $100,000,000,000. Even if it is an accurate assessment, somebody could randomly luck into a vulnerability that would normally actually take $100,000,000,000 to find and suddenly you are dead since it is…

> It would, however, provide very strong evidence No it wouldn't, because-- > the risk of getting unlucky -- oh, you do understand. Why are you proposing this again?

Because you can use statistics to analyze random events. A claim that your system requires resources on the order of $100,000,000 to breach can be converted, assuming a rate of $300,000/engineer-year to a statement like: "Your system will require on average 300 engineer-years to breach." If the first person who tries is able to breach your system after 1 engineer-year that is an indication that maybe your calculations are incorrect. If it happens again after 1 engineer-year then you have almost absolutely incorrectly determined your true failure rate. If it repeatedly happens over and over again then you are wrong and, conveniently, you will promptly go out of business as people arbitrage your lies. If, however, your analysis is correct, then the probability of getting unlucky multiple times relative to your true failure rate is highly unlikely and the outcomes will stabilize in the long run. Assuming you did not set the payout so high as to be instant death, which I did suggest in FireEye's case as FireEye can, in fact, support a $100,000,000 payout, it provides a relatively sound, objective, statistical basis for inferring the actual cost.

Re: FireEye Shares Details of Recent Cyber Attack

#173

Earlier quoted context omitted.

The FBI has confirmed the state-level adversary thing in a release today. There is no love lost between the outgoing administration and FireEye. You're probably never going to get evidence that will satisfy a message board. The Wikileaks post you cited repeats the fallacy I mentioned earlier --- the idea that analysts are simply attributing exploit code. I think if you stop and think about it, you can probably rattle…

No, I am not saying a bored teenager can create evidence like that, but the sophisticated nation states surely can, and probably some other larger orgs, too. Code can be faked, meta data can be faked, MO can be imitated, and so on. And the nation states at the very least - and their contractors and (former) employees in the areas of concern - will know what it has to look like. Motive isn't always clear, and quite of…

You said "I wouldn't discount a bored teenager". We have now mutually discounted a bored teenager.

Re: FireEye Shares Details of Recent Cyber Attack

#174

Earlier quoted context omitted.

No, I am not saying a bored teenager can create evidence like that, but the sophisticated nation states surely can, and probably some other larger orgs, too. Code can be faked, meta data can be faked, MO can be imitated, and so on. And the nation states at the very least - and their contractors and (former) employees in the areas of concern - will know what it has to look like. Motive isn't always clear, and quite of…

You said "I wouldn't discount a bored teenager". We have now mutually discounted a bored teenager.

I haven't yet, because all I have to go by is claims by FireEye and the FBI. I already said why I take what FireEye says with a grain of salt, and frankly, I also take what the FBI says with more than a grain of salt. The FBI is inherently political, and even when they are not, they are known to make up stuff when it suits them (e.g. "parallel construction").

That may be a rather untrusting/paranoid mindset that I employ, but it worked for me so far.

Re: FireEye Shares Details of Recent Cyber Attack

#175
post #119
post #109

Earlier quoted context omitted.

> Matthew in accounting that will open that invoice attachment so he can pay it. Matthew in accounting shouldn't have permission to run an untrusted binary.

...and a binary at all should not be able to be downloaded from the internet or pass through and email server. Additionally the only binary files running on any system should be known binaries. Least Privileged systems with tight change control don’t get hacked.

Senior leadership would take an incredibly dim view when this inevitably shuts down accounting and purchasing after they can't use their PDFs and other executable-code documents anymore.

Re: FireEye Shares Details of Recent Cyber Attack

#176

Earlier quoted context omitted.

You said "I wouldn't discount a bored teenager". We have now mutually discounted a bored teenager.

I haven't yet, because all I have to go by is claims by FireEye and the FBI. I already said why I take what FireEye says with a grain of salt, and frankly, I also take what the FBI says with more than a grain of salt. The FBI is inherently political, and even when they are not, they are known to make up stuff when it suits them (e.g. "parallel construction"). That may be a rather untrusting/paranoid mindset that I em…

Asking sincerely: is there some particular reason it should matter to the rest of us whether your perspective on attack attribution has "worked for you so far"? What would the consequences to you have been had your intuition not "worked"?

Re: FireEye Shares Details of Recent Cyber Attack

#177
post #84
post #78

> FireEye CEO Mandia wrote that none of the red team tools exploited so-called “zero-day vulnerabilities,” meaning the relevant flaws should already be public. Seems like a massive amount of energy to devote to stealing tools, that by and large, probably have public equivalents sitting around on GitHub.

It is. It's equally likely that the direct goal of this attack was simply to harm FireEye.

That's interesting. My first thought was that the attacker wanted access to internal red team tools under the assumption that resulting indicators would be ignored by the blue team, making attacks against their customers less likely to be detected. Wanting to harm FireEye directly is certainly a more simple explanation.

Re: FireEye Shares Details of Recent Cyber Attack

#178
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

Wonder how many of those signatures are suddenly going to light up as existing tools used besides FireEye.

Re: FireEye Shares Details of Recent Cyber Attack

#179

Earlier quoted context omitted.

I haven't yet, because all I have to go by is claims by FireEye and the FBI. I already said why I take what FireEye says with a grain of salt, and frankly, I also take what the FBI says with more than a grain of salt. The FBI is inherently political, and even when they are not, they are known to make up stuff when it suits them (e.g. "parallel construction"). That may be a rather untrusting/paranoid mindset that I em…

Asking sincerely: is there some particular reason it should matter to the rest of us whether your perspective on attack attribution has "worked for you so far"? What would the consequences to you have been had your intuition not "worked"?

Replying sincerely: It matters the same way as your own opinion matters to the rest of us.

And consequences? In this case, probably none. We're here for news and entertainment, and reasoning about topics such as this one is enjoyable to me. But lively discussions and their takeaways can inform future arguments and decisions.

But in more general terms, I am a member of the electorate in my country, and misattributions and/or bad or even fake evidence quite often have direct influence on policy. E.g. I was quite happy that I, along with a majority of my fellow citizens, did not believe the "conclusive" "evidence" of WMDs in Iraq the US had put forth, and stayed out of that war.

Re: FireEye Shares Details of Recent Cyber Attack

#180
post #10

The problem with these articles is the cloak and dagger nature of these stories and the lack of healthy skepticism. While not necessarily the case here, every big tech company puts blame on an APT aka a nation state actor. In fact, the very same FireEye attributed the Sony Pictures hack to North Korea on extremely flimsy grounds. By those same measures one could have implicated East Palo Alto High School. You never r…

> The U.S. Department of Justice issued formal charges related to the Sony hack on North Korean citizen Park Jin-hyok on September 6, 2018. ... The Department of Justice had previously identified Park and had been monitoring him for some time, but could not indict him immediately as much of the information around him was classified.
Post reply on HN