Earlier quoted context omitted.
>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way
How do you get updates to your airgapped hardware? That's your attack vector.
FireEye Shares Details of Recent Cyber Attack
181–190 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#182Earlier quoted context omitted.
Likely you want to transfer data from an airgapped computer and back. So you need some way of transferring it.
It’s not obvious to me why engineering and accounting should need to transfer any data and back forth beyond basic email communications.
Even if you got all of the issues caused by e-mails figured out, somehow you have to transfer them from one network to another. You'll either have to poke holes into your firewall or use USB sticks.
My point is: even in airgapped networks you usually want to exchange some data. The moment you want to exchange data, you have a path where a virus can be smuggled in.
Re: FireEye Shares Details of Recent Cyber Attack
#183Earlier quoted context omitted.
> Matthew in accounting that will open that invoice attachment so he can pay it. This is painfully accurate. A chain is really only as strong as its weakest link :/
The invoice should be a PDF interpreted by pdf.js inside a sandboxed browser. Even better is that the company should have its own internal ordering system.
It would be really cool to have an invoice format that contains payment and tax information in a machine readable way and a way to send that information around with a verifiable channel.
Re: FireEye Shares Details of Recent Cyber Attack
#184Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…
See for example: https://www.washingtonpost.com/national-security/pompeo-says... https://foreignpolicy.com/2020/01/24/crowdstrike-trump-impea...
Russian government doesn’t do any hacking, it’s all a fabrication by the Democrats :)
Re: FireEye Shares Details of Recent Cyber Attack
#185From their official blog post: > Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities. I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?
IANASecurityExpert. Claiming that an adversary is a state actor seems as much about magnifying the threat as a genuine finding. A high school kid exploiting their weaknesses will obviously leave them red faced. Seems like an natural position to take for anyone hacked. Not saying it didn't happen, but it looks like it has become the goto defense in recent times.
Re: FireEye Shares Details of Recent Cyber Attack
#186Earlier quoted context omitted.
Matthew in accounting should be given an ipad pro instead of a laptop or pc, with a glued in lightning cable that can only do power. ^ This is the solution I have been mulling if and when I am responsible for an org where security is kinda important. Sure, iOS is still hackable, but hopefully we put more hindrance steps between the attacker and the org, and move the exposure more to the cloud services (like box). Cur…
99.9% of Matthews-in-accounting use Microsoft Excel on Windows. Full stop.
Re: FireEye Shares Details of Recent Cyber Attack
#187Earlier quoted context omitted.
Likely you want to transfer data from an airgapped computer and back. So you need some way of transferring it.
It’s not obvious to me why engineering and accounting should need to transfer any data and back forth beyond basic email communications.
Re: FireEye Shares Details of Recent Cyber Attack
#188Earlier quoted context omitted.
Matthew in accounting should be given an ipad pro instead of a laptop or pc, with a glued in lightning cable that can only do power. ^ This is the solution I have been mulling if and when I am responsible for an org where security is kinda important. Sure, iOS is still hackable, but hopefully we put more hindrance steps between the attacker and the org, and move the exposure more to the cloud services (like box). Cur…
Matthew wouldn't want to work at your shit company then.
Re: FireEye Shares Details of Recent Cyber Attack
#189Earlier quoted context omitted.
The invoice should be a PDF interpreted by pdf.js inside a sandboxed browser. Even better is that the company should have its own internal ordering system.
The invoice shouldn’t have to be a PDF and shouldn’t have to be sent via e-mail. Sadly those are still the best tools we have. It would be really cool to have an invoice format that contains payment and tax information in a machine readable way and a way to send that information around with a verifiable channel.
pdf.js lacks capabilities to extract the XML or verify signatures, so the usual way will be to use Acrobat Reader or the usual bunch of "industry-standard" invoice-processing crap that now suddenly has to deal with malicious input.
The idea to do it differently might be nice in theory, but is lacking a smooth way to change over from the old paper-invoice ways. PDF will be the thing for some decades and we will have to deal with it.
Re: FireEye Shares Details of Recent Cyber Attack
#190Earlier quoted context omitted.
They have a reputation for making up salacious stories based on totally inconclusive, inadequate "evidence". No wonder they turned it up to 11 when it was themselves getting breached.
Can you describe what you'd consider adequate and conclusive evidence necessary for attribution of a cyberattack?
Attribution is hard to impossible. What passes for attribution these days is laughable.