Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

231–240 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#231
post #65

Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…

It does seem paranoid to think that someone viewing something like this with scepticism makes them a state actor. I think there have been too many incidents of companies crying wolf for people to think otherwise. This is a forum for discussion and to accuse people with alternative views of being state actors probably just adds fuel to the fire.

Re: FireEye Shares Details of Recent Cyber Attack

#232
post #190

Earlier quoted context omitted.

Can you describe what you'd consider adequate and conclusive evidence necessary for attribution of a cyberattack?

Documentation verifiably obtained from the attacker about the intent to attack, the methods used, the results and people involved. Preferrably with means to tie everything to a plausible timeline. Attribution is hard to impossible. What passes for attribution these days is laughable.

Would you require this level of certainty when prosecuting crimes domestically? Why or why not?

Short of a full written confession, is there any way whatsoever to gain an understanding of who perpetrated an attack? Or are you saying it’s impossible to even begin to build evidence?

Re: FireEye Shares Details of Recent Cyber Attack

#234
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

In your first sentence you say why fingerprinting is bad but then say they did a good job by releasing fingerprints?

Am I missing something?

Re: FireEye Shares Details of Recent Cyber Attack

#235
post #65

Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…

It does seem paranoid to think that someone viewing something like this with scepticism makes them a state actor. I think there have been too many incidents of companies crying wolf for people to think otherwise. This is a forum for discussion and to accuse people with alternative views of being state actors probably just adds fuel to the fire.

But all of these comments are fundamentally not helpful either. They all basically boil down to calling FireEye unreliable, which is fine if you actually back it up with discussion. But that's not what they are doing. They just assert that FireEye can't be believed without any reasoning or evidence.

Re: FireEye Shares Details of Recent Cyber Attack

#236
post #63
post #56

Earlier quoted context omitted.

>Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. While this is true for e.g., Equifax (see https://ciexinc.com/blog/quick-assessment-of-a-companys-secu... ), if FireEye (aka Mandiant) says it, I tend to believe it to be quite true. I would expect that hacking…

First, FireEye was one of the companies who worked to secure Equifax prior to the breach as mentioned by the CSO of Equifax on page 4 of this FireEye white paper from 2012 [1] that FireEye has since retracted [2][3]. Second, that is kind of a non-sequitur. I did not say that a nation-state did not pull off the attack, my gripe is that they are implying, like every other company that gets breached, that only a nation-…

>my gripe is that they are implying, like every other company that gets breached, that only a nation-state has the resources to pull off such an attack with their wording.

I feel that with respect to FireEye, that it isn't just an implication; more that they would claim this with strong evidence. They are about attribution.

I think this argument is making some false equivalence. Just because every other company that was breached (e.g. Equifax) claims "Wow State Actor Sophisticate Beyond Anything Before Seen By Man" for something as simple as failure to update your software leaves a yawning hole has tarnished the dialog for those who know what they are doing.

While CSO at Relativity, and now for my clients, I strongly suggest that you don't use the phrase "Security is Very Important to us" since that is the first thing out of the mouth of companies who didn't until they got hacked.

>Do you think a penetration test of 3 engineers working fulltime for a year would fail to materially breach FireEye's corporate systems?

Bluntly, yes. I expect that their defenses are much better than most companies, including security companies.

>I have literally never heard of a single person in enterprise security who has ever dared to make such a remark on the record

Enterprise security is in a different category altogether. Few non-security enterprises will withstand much of an attack. FireEye is in a different category altogether.

If you are interested in the topic, a useful book to read is https://www.amazon.com/Incident-Response-Computer-Forensics-.... I think this is more informative than these BOEC cost calculations.

Re: FireEye Shares Details of Recent Cyber Attack

#237
post #65

Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…

I think one reason is that easily-breached enterprises have used such language in many forms over the years to try to excuse themselves from being weak on security. So when one credibly gets hacked by an actual state actor, the words conjure up the false claims.

Re: FireEye Shares Details of Recent Cyber Attack

#238

Earlier quoted context omitted.

I haven't yet, because all I have to go by is claims by FireEye and the FBI. I already said why I take what FireEye says with a grain of salt, and frankly, I also take what the FBI says with more than a grain of salt. The FBI is inherently political, and even when they are not, they are known to make up stuff when it suits them (e.g. "parallel construction"). That may be a rather untrusting/paranoid mindset that I em…

Asking sincerely: is there some particular reason it should matter to the rest of us whether your perspective on attack attribution has "worked for you so far"? What would the consequences to you have been had your intuition not "worked"?

>That may be a rather untrusting/paranoid mindset that I employ, but it worked for me so far.

"Worked for me so far" can turn out to be inadequate if you discover that your stuff has been leaking to the bad guys for a year.

Re: FireEye Shares Details of Recent Cyber Attack

#239
post #66

Earlier quoted context omitted.

Well they could pretty easily demonstrate that only a state actor could pull off an attack like this in an objective manner. If it takes state-level resources to breach their systems, then they can just announce and put out an open prize for anybody who can breach their systems that pays out less than state-level resources. If it actually takes state-level resources to breach their systems, but pays out less than tha…

I'd counter with the following argument. I believe not a single cyber offensive op performed by a nation state had a budget of $1B. I'd say $1M is an upper bound here. Cyber warfare is used because it's cheap.

My comment is not arguing whether a state actor breached FireEye, but whether only a state actor could breach FireEye as they are implying as nobody else could fund or develop such a "sophisticated" or "advanced" attack. If it is at most $1M as you say, then you are actually agreeing with me as that would hardly constitute something that only a "state actor" could do given that literally any mid-sized business, of which there are millions, could support such an expense. To actually demonstrate that it is so difficult to develop that "only a state actor" has the resources to develop/deploy such an attack should require demonstrating that it is out of reach for all but a state actor for which a $1B budget is likely a good bottom-end as only a very small number of non-state entities can actually support such an effort. I hope that clarifies my point.

Re: FireEye Shares Details of Recent Cyber Attack

#240
post #172

Earlier quoted context omitted.

> It would, however, provide very strong evidence No it wouldn't, because-- > the risk of getting unlucky -- oh, you do understand. Why are you proposing this again?

Because you can use statistics to analyze random events. A claim that your system requires resources on the order of $100,000,000 to breach can be converted, assuming a rate of $300,000/engineer-year to a statement like: "Your system will require on average 300 engineer-years to breach." If the first person who tries is able to breach your system after 1 engineer-year that is an indication that maybe your calculation…

Ah. The premise of "let people hack you, and pay out a bounty, not just once but dozens of times so you get decent statistics" was not explicit in your proposal, but definitely makes it even less attractive.
Post reply on HN