Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

211–220 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#211
post #66
post #18

Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.

Well they could pretty easily demonstrate that only a state actor could pull off an attack like this in an objective manner. If it takes state-level resources to breach their systems, then they can just announce and put out an open prize for anybody who can breach their systems that pays out less than state-level resources. If it actually takes state-level resources to breach their systems, but pays out less than tha…

I'd counter with the following argument.

I believe not a single cyber offensive op performed by a nation state had a budget of $1B. I'd say $1M is an upper bound here. Cyber warfare is used because it's cheap.

Re: FireEye Shares Details of Recent Cyber Attack

#212

According to Reuters, a Western security official claims similar companies have been affected in a similar way to FireEye [1]. It will be interesting to see how this plays out, and if true, this may be the first of many compromises to be revealed. [1] https://twitter.com/Bing_Chris/status/1336431664478687239

I salivate at the potential of seeing the industry turned on it's head and these tools being leaked. I know there are great firms out there, but a lot are snake oil nonsense.

Re: FireEye Shares Details of Recent Cyber Attack

#213
post #108

From their official blog post: > Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities. I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?

Very few companies will publicly attribute attacks to a specific government - both because it is hard and because of potential political blowback. I would confidently say that the top 50 countries by GDP have a solid offensive capability. Some, like Japan, have very specific interests that don't align with what makes the news. At some point you start getting in to the territory of Hacking Team, NSO Group, Gamma, VAST…

Thanks. Any more info on the Japanese stuff you mention? I don't often hear about that (as you state)

Re: FireEye Shares Details of Recent Cyber Attack

#214
post #66

Earlier quoted context omitted.

Well they could pretty easily demonstrate that only a state actor could pull off an attack like this in an objective manner. If it takes state-level resources to breach their systems, then they can just announce and put out an open prize for anybody who can breach their systems that pays out less than state-level resources. If it actually takes state-level resources to breach their systems, but pays out less than tha…

I'd counter with the following argument. I believe not a single cyber offensive op performed by a nation state had a budget of $1B. I'd say $1M is an upper bound here. Cyber warfare is used because it's cheap.

Spezialized custom work is expensive.

I doubt Stuxnet cost only $1M.

Licensing costs for law enforcement "remote access tools" (state trojans) can be millions (distributed among dozens of uses, but IMHO easy to see spending as much on a high-value single use).

From the wiki article about the iPhone-encryption debate: "On April 7, 2016, FBI Director James Comey said that the tool used can only unlock an iPhone 5C like that used by the San Bernardino shooter, as well as older iPhone models lacking the Touch ID sensor. Comey also confirmed that the tool was purchased from a third party but would not reveal the source,[59] later indicating the tool cost more than $1.3 million and that they did not purchase the rights to technical details about how the tool functions"

Re: FireEye Shares Details of Recent Cyber Attack

#215
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

> Matthew in accounting that will open that invoice attachment so he can pay it. This is painfully accurate. A chain is really only as strong as its weakest link :/

If Matthew in accounting received a malicious attachment then IT has already failed.

Re: FireEye Shares Details of Recent Cyber Attack

#216

Earlier quoted context omitted.

Does Matthew in accounting need access to the same network as the engineering staff?

Air gap is not the final word in security. Stuxnet got into the Iranian centrifuges despite an air gap.

If we only have a single example of their defeat in the last more than a decade, I'd say that's evidence they're a pretty good word.

What other security features claim that performance?

Re: FireEye Shares Details of Recent Cyber Attack

#217

Earlier quoted context omitted.

We (as in the IT Sec industry including me) prefer to blame Matthew. Or my 80 year old mother for not installing the latest Adobe patches in real time. With 30 years of daily experience in this field, I am ashamed about how we fail Matthew & my mother in the sense that they can still not just enjoy the internet and open random emails without one of us blaming them for how stupid they are.

Do we somehow fail the dumb accountant or 80 year gma with cars because they can't just get in and drive without learning how to drive?

An analogy with cars would be your 80 year grandma gets a prompt on her dash to install an update. Turns out it’s malicious and hacks her car.

Leaning to driving is not the correct analogy. Almost everyone can use a mouse or a touch screen to operate a computer.

Re: FireEye Shares Details of Recent Cyber Attack

#218
post #47
post #31

Earlier quoted context omitted.

> Why say that? Why not just say you were attacked and going to try and determine why and make any changes Because they would be out of business tomorrow if they say they think it was a 13 year old from Ohio just fooling around on a Sunday. This is FireEye marketing itself for the F500 by selling fear of an invisible adversary with unlimited resources that already deliver innovative black hat capabilities.

> if they say they think it was a 13 year old from Ohio How could you read my comment and think that is what I thought they should say?? I said not to say anything. And why use hyperbole ie 'they would be out of business tomorrow'. And no it's not marketing anymore than if a Karate expert airs that he was beat up in an alley and then says 'but the person was 9 feet tall that's why!'. (But sure to your point if they s…

But your oneliner leaves that much range open for interpretation and if a company is not this specific journalist are going to speculate because even the FBI has had 13 year olds harvesting chaos in their ecosystem.

Re: FireEye Shares Details of Recent Cyber Attack

#219

Earlier quoted context omitted.

We (as in the IT Sec industry including me) prefer to blame Matthew. Or my 80 year old mother for not installing the latest Adobe patches in real time. With 30 years of daily experience in this field, I am ashamed about how we fail Matthew & my mother in the sense that they can still not just enjoy the internet and open random emails without one of us blaming them for how stupid they are.

Do we somehow fail the dumb accountant or 80 year gma with cars because they can't just get in and drive without learning how to drive?

You can't compare this. There are much less bad actors in mobile traffic that constantly try to steal your keys, try to suck gas from your gas tank, hide in your trunk or trick you into insurance fraud...

Re: FireEye Shares Details of Recent Cyber Attack

#220

Earlier quoted context omitted.

Do we somehow fail the dumb accountant or 80 year gma with cars because they can't just get in and drive without learning how to drive?

That analogy doesn't work in my opinion, because to even be allowed to drive, an extensive amount of training is required. I think we need to start very early. There should be more mandatory comouter science and information security classes at schools because we are all confronted with these topics everyday. Most people can work systems such as washing machines, vacuum cleaners and so on, the problems arise when the…

I blame the way we design our computer systems. For some reason, every program a user runs on a desktop computer has full access to every file saved by every other program. And full network access, and a slew of other permissions. In seconds a single malicious program can make a right mess of things, or exfiltrate sensitive data. A ransomware attack hit a large aged care provider in Australia recently and encrypted the files listing which medication to administer. How? I’d guess that every program on every computer in their network has full write access to their network shares. We made these attacks easy to pull off with our insecure by default designs.

It’s like we’ve given every Tom, Dick and Harry a F1 supercar then we blame them when they crash the thing. The mistake is ours for not making better security models. Desktop apps should be sandboxed by default, and isolated like we isolate phone apps. For all the justifiable fear people have about apple’s control over what software can run on their machines, I think the app sandboxing and signing security model they’re working towards is the right one for 95% of computer users.

Post reply on HN