Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…
FireEye Shares Details of Recent Cyber Attack
231–240 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#232Earlier quoted context omitted.
Can you describe what you'd consider adequate and conclusive evidence necessary for attribution of a cyberattack?
Documentation verifiably obtained from the attacker about the intent to attack, the methods used, the results and people involved. Preferrably with means to tie everything to a plausible timeline. Attribution is hard to impossible. What passes for attribution these days is laughable.
Short of a full written confession, is there any way whatsoever to gain an understanding of who perpetrated an attack? Or are you saying it’s impossible to even begin to build evidence?
Re: FireEye Shares Details of Recent Cyber Attack
#233Re: FireEye Shares Details of Recent Cyber Attack
#234As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
Am I missing something?
Re: FireEye Shares Details of Recent Cyber Attack
#235Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…
It does seem paranoid to think that someone viewing something like this with scepticism makes them a state actor. I think there have been too many incidents of companies crying wolf for people to think otherwise. This is a forum for discussion and to accuse people with alternative views of being state actors probably just adds fuel to the fire.
Re: FireEye Shares Details of Recent Cyber Attack
#236Earlier quoted context omitted.
>Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. While this is true for e.g., Equifax (see https://ciexinc.com/blog/quick-assessment-of-a-companys-secu... ), if FireEye (aka Mandiant) says it, I tend to believe it to be quite true. I would expect that hacking…
First, FireEye was one of the companies who worked to secure Equifax prior to the breach as mentioned by the CSO of Equifax on page 4 of this FireEye white paper from 2012 [1] that FireEye has since retracted [2][3]. Second, that is kind of a non-sequitur. I did not say that a nation-state did not pull off the attack, my gripe is that they are implying, like every other company that gets breached, that only a nation-…
I feel that with respect to FireEye, that it isn't just an implication; more that they would claim this with strong evidence. They are about attribution.
I think this argument is making some false equivalence. Just because every other company that was breached (e.g. Equifax) claims "Wow State Actor Sophisticate Beyond Anything Before Seen By Man" for something as simple as failure to update your software leaves a yawning hole has tarnished the dialog for those who know what they are doing.
While CSO at Relativity, and now for my clients, I strongly suggest that you don't use the phrase "Security is Very Important to us" since that is the first thing out of the mouth of companies who didn't until they got hacked.
>Do you think a penetration test of 3 engineers working fulltime for a year would fail to materially breach FireEye's corporate systems?
Bluntly, yes. I expect that their defenses are much better than most companies, including security companies.
>I have literally never heard of a single person in enterprise security who has ever dared to make such a remark on the record
Enterprise security is in a different category altogether. Few non-security enterprises will withstand much of an attack. FireEye is in a different category altogether.
If you are interested in the topic, a useful book to read is https://www.amazon.com/Incident-Response-Computer-Forensics-.... I think this is more informative than these BOEC cost calculations.
Re: FireEye Shares Details of Recent Cyber Attack
#237Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…
Re: FireEye Shares Details of Recent Cyber Attack
#238Earlier quoted context omitted.
I haven't yet, because all I have to go by is claims by FireEye and the FBI. I already said why I take what FireEye says with a grain of salt, and frankly, I also take what the FBI says with more than a grain of salt. The FBI is inherently political, and even when they are not, they are known to make up stuff when it suits them (e.g. "parallel construction"). That may be a rather untrusting/paranoid mindset that I em…
Asking sincerely: is there some particular reason it should matter to the rest of us whether your perspective on attack attribution has "worked for you so far"? What would the consequences to you have been had your intuition not "worked"?
"Worked for me so far" can turn out to be inadequate if you discover that your stuff has been leaking to the bad guys for a year.
Re: FireEye Shares Details of Recent Cyber Attack
#239Earlier quoted context omitted.
Well they could pretty easily demonstrate that only a state actor could pull off an attack like this in an objective manner. If it takes state-level resources to breach their systems, then they can just announce and put out an open prize for anybody who can breach their systems that pays out less than state-level resources. If it actually takes state-level resources to breach their systems, but pays out less than tha…
I'd counter with the following argument. I believe not a single cyber offensive op performed by a nation state had a budget of $1B. I'd say $1M is an upper bound here. Cyber warfare is used because it's cheap.
Re: FireEye Shares Details of Recent Cyber Attack
#240Earlier quoted context omitted.
> It would, however, provide very strong evidence No it wouldn't, because-- > the risk of getting unlucky -- oh, you do understand. Why are you proposing this again?
Because you can use statistics to analyze random events. A claim that your system requires resources on the order of $100,000,000 to breach can be converted, assuming a rate of $300,000/engineer-year to a statement like: "Your system will require on average 300 engineer-years to breach." If the first person who tries is able to breach your system after 1 engineer-year that is an indication that maybe your calculation…