Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

181–190 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#181

Earlier quoted context omitted.

>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way

How do you get updates to your airgapped hardware? That's your attack vector.

you don't

Re: FireEye Shares Details of Recent Cyber Attack

#182
post #136

Earlier quoted context omitted.

Likely you want to transfer data from an airgapped computer and back. So you need some way of transferring it.

It’s not obvious to me why engineering and accounting should need to transfer any data and back forth beyond basic email communications.

Email seems simple to you, but in fact it's an incredibly complicated protocol, so software treating it is likely to have many (exploitable) bugs. Also, there are attachments. Those are the classical way to hack many places.

Even if you got all of the issues caused by e-mails figured out, somehow you have to transfer them from one network to another. You'll either have to poke holes into your firewall or use USB sticks.

My point is: even in airgapped networks you usually want to exchange some data. The moment you want to exchange data, you have a path where a virus can be smuggled in.

Re: FireEye Shares Details of Recent Cyber Attack

#183
post #129

Earlier quoted context omitted.

> Matthew in accounting that will open that invoice attachment so he can pay it. This is painfully accurate. A chain is really only as strong as its weakest link :/

The invoice should be a PDF interpreted by pdf.js inside a sandboxed browser. Even better is that the company should have its own internal ordering system.

The invoice shouldn’t have to be a PDF and shouldn’t have to be sent via e-mail. Sadly those are still the best tools we have.

It would be really cool to have an invoice format that contains payment and tax information in a machine readable way and a way to send that information around with a verifiable channel.

Re: FireEye Shares Details of Recent Cyber Attack

#184
post #65

Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…

It’s a widespread talking point among the QAnon crowd.

See for example: https://www.washingtonpost.com/national-security/pompeo-says... https://foreignpolicy.com/2020/01/24/crowdstrike-trump-impea...

Russian government doesn’t do any hacking, it’s all a fabrication by the Democrats :)

Re: FireEye Shares Details of Recent Cyber Attack

#185

From their official blog post: > Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities. I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?

IANASecurityExpert. Claiming that an adversary is a state actor seems as much about magnifying the threat as a genuine finding. A high school kid exploiting their weaknesses will obviously leave them red faced. Seems like an natural position to take for anyone hacked. Not saying it didn't happen, but it looks like it has become the goto defense in recent times.

Bluffing would be very risky, if turned out the attacker really was a high school kid, or the exploit was trivial. I am inclined to believe them.

Re: FireEye Shares Details of Recent Cyber Attack

#186

Earlier quoted context omitted.

Matthew in accounting should be given an ipad pro instead of a laptop or pc, with a glued in lightning cable that can only do power. ^ This is the solution I have been mulling if and when I am responsible for an org where security is kinda important. Sure, iOS is still hackable, but hopefully we put more hindrance steps between the attacker and the org, and move the exposure more to the cloud services (like box). Cur…

99.9% of Matthews-in-accounting use Microsoft Excel on Windows. Full stop.

Excel in windows is still possible, it'll just be on either an rdp server locally or on AWS.

Re: FireEye Shares Details of Recent Cyber Attack

#187
post #136

Earlier quoted context omitted.

Likely you want to transfer data from an airgapped computer and back. So you need some way of transferring it.

It’s not obvious to me why engineering and accounting should need to transfer any data and back forth beyond basic email communications.

Single sign on etc: usually there's a resource that everyone in the company needs to use. Besides, email is a major infection vector.

Re: FireEye Shares Details of Recent Cyber Attack

#188
post #163

Earlier quoted context omitted.

Matthew in accounting should be given an ipad pro instead of a laptop or pc, with a glued in lightning cable that can only do power. ^ This is the solution I have been mulling if and when I am responsible for an org where security is kinda important. Sure, iOS is still hackable, but hopefully we put more hindrance steps between the attacker and the org, and move the exposure more to the cloud services (like box). Cur…

Matthew wouldn't want to work at your shit company then.

Why is that a mark of a shit company exactly? Because we should continue allowing a threat model that continues to plague essential services like hospitals with "ransomware", the fact that such a threat is allowed to continue suggests we need to take a hard look at how much we should take highly customisable computers for granted in work situations.

Re: FireEye Shares Details of Recent Cyber Attack

#189
post #129

Earlier quoted context omitted.

The invoice should be a PDF interpreted by pdf.js inside a sandboxed browser. Even better is that the company should have its own internal ordering system.

The invoice shouldn’t have to be a PDF and shouldn’t have to be sent via e-mail. Sadly those are still the best tools we have. It would be really cool to have an invoice format that contains payment and tax information in a machine readable way and a way to send that information around with a verifiable channel.

The invoice will be PDF with an embedded XML blob containing the machine-readable data part, signed with a PDF signature: https://www.pdf-tools.com/pdf20/en/zugferd/

pdf.js lacks capabilities to extract the XML or verify signatures, so the usual way will be to use Acrobat Reader or the usual bunch of "industry-standard" invoice-processing crap that now suddenly has to deal with malicious input.

The idea to do it differently might be nice in theory, but is lacking a smooth way to change over from the old paper-invoice ways. PDF will be the thing for some decades and we will have to deal with it.

Re: FireEye Shares Details of Recent Cyber Attack

#190
post #51

Earlier quoted context omitted.

They have a reputation for making up salacious stories based on totally inconclusive, inadequate "evidence". No wonder they turned it up to 11 when it was themselves getting breached.

Can you describe what you'd consider adequate and conclusive evidence necessary for attribution of a cyberattack?

Documentation verifiably obtained from the attacker about the intent to attack, the methods used, the results and people involved. Preferrably with means to tie everything to a plausible timeline.

Attribution is hard to impossible. What passes for attribution these days is laughable.

Post reply on HN