Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

241–250 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#241
post #236
post #63

Earlier quoted context omitted.

First, FireEye was one of the companies who worked to secure Equifax prior to the breach as mentioned by the CSO of Equifax on page 4 of this FireEye white paper from 2012 [1] that FireEye has since retracted [2][3]. Second, that is kind of a non-sequitur. I did not say that a nation-state did not pull off the attack, my gripe is that they are implying, like every other company that gets breached, that only a nation-…

>my gripe is that they are implying, like every other company that gets breached, that only a nation-state has the resources to pull off such an attack with their wording. I feel that with respect to FireEye, that it isn't just an implication; more that they would claim this with strong evidence. They are about attribution. I think this argument is making some false equivalence. Just because every other company that…

FireEye literally did the incident response for the Equifax hack, so I do not see how you can claim: "FireEye does accurate and honest attribution." but then also claim "Equifax likely made stuff up." unless you are claiming that FireEye was involved in incident response, but was somehow not involved in attribution, or that they made a true discovery-able report, but knowingly lied.

It is hardly a false equivalence. If everybody constantly fails with little to no evidence of any success by anyone ever despite continuous assurances of success by everyone, there is exactly zero evidence that a layperson should trust any statement on that topic without good, solid, objective evidence to the contrary. Given the track record in the industry, there is no reason to give the benefit of the doubt to any company. The burden of proof is on them to demonstrate their claims in a relatively objective, quantitative manner. If they have no means of proving a quantitative claim in a relatively objective manner, there is no reason to believe their claims given their track record. To provide an analogy, if somebody you trust to not be malicious asks you to follow them, but they can not justify why, then the smart thing to do is judge them based on their track record as that provides some part of an objective statistical basis for evaluating their prevailing success rate.

If you really must have evidence of a trend of insecurity amongst security companies. Then we can look no further than McAfee, Symantec, and Trend Micro all being breached between 2017-2019 that was attributed to "fxmsp" [1][2], a private Russian hacking group that was selling the contents of the breaches for a few $100k which demonstrates how easy it must have been for it to be profitable at that price point (to be fair they could sell it multiple times, but I doubt they sold it hundreds of times). So, what justification do you have for why FireEye's security should be any different than other companies or even other security companies?

Also, you only provided an answer to the low end of "easy" rather than the high end at 30 engineers for a year or 10 engineers for 3 years which would be needed to pull them out of the "easy" category by my standards. If you do claim they can survive that, can you provide either some reasonably quantitative evidence or public statements to that effect or the same for literally any other company in the world you think can do so as I have not once ever heard of a single company ever justifying such a claim in any verifiable manner. Thank you.

[1] https://gdpr.report/news/2019/05/15/mcafeesymantec-trend-mic...

[2] https://www.zdnet.com/article/fxmsp-hacker-indicted-by-feds-...

Re: FireEye Shares Details of Recent Cyber Attack

#242

Earlier quoted context omitted.

99.9% of Matthews-in-accounting use Microsoft Excel on Windows. Full stop.

Excel in windows is still possible, it'll just be on either an rdp server locally or on AWS.

And then when you run the xlsx file with the contaminated macro or zero-day, the result is exactly the same.

Re: FireEye Shares Details of Recent Cyber Attack

#243
post #190

Earlier quoted context omitted.

Documentation verifiably obtained from the attacker about the intent to attack, the methods used, the results and people involved. Preferrably with means to tie everything to a plausible timeline. Attribution is hard to impossible. What passes for attribution these days is laughable.

Would you require this level of certainty when prosecuting crimes domestically? Why or why not? Short of a full written confession, is there any way whatsoever to gain an understanding of who perpetrated an attack? Or are you saying it’s impossible to even begin to build evidence?

That is pretty much the level of certainty required for prosecuting crimes domestically, yes, or very close to it. Time-frame, proof of intent, and motive.

There is of course a way of doing so, as long as the attacker made a mistake. If they didn't, then it very well might be completely impossible to know who did it, and that's just how it is.

Re: FireEye Shares Details of Recent Cyber Attack

#244
post #65

Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…

I'm not tied in any way to a nation state hacking group, and through my albeit limited experience in cybersecurity it's clear to me that most attacks attributed to nation state actors could probably have been done by private ventures.

And there is, of course, very strong incentive to make such claims.

I'd imagine my experience isn't unique, and that many people came to the same conclusion.

I'd say that your conclusion isn't warranted.

There have been comments stating with high detail why exactly it's probably not a nation state actor, but ultimately it's a case of the burden of proof being on the party that makes the claim, and generally those parties just can't substantiate it.

Re: FireEye Shares Details of Recent Cyber Attack

#245

Earlier quoted context omitted.

Would you require this level of certainty when prosecuting crimes domestically? Why or why not? Short of a full written confession, is there any way whatsoever to gain an understanding of who perpetrated an attack? Or are you saying it’s impossible to even begin to build evidence?

That is pretty much the level of certainty required for prosecuting crimes domestically, yes, or very close to it. Time-frame, proof of intent, and motive. There is of course a way of doing so, as long as the attacker made a mistake. If they didn't, then it very well might be completely impossible to know who did it, and that's just how it is.

Timeframe, proof of intent, and motive are not what the commenter I replied to said, and they most certainly have those three pieces of information when attribution takes place generally speaking.

Re: FireEye Shares Details of Recent Cyber Attack

#246

Earlier quoted context omitted.

That is pretty much the level of certainty required for prosecuting crimes domestically, yes, or very close to it. Time-frame, proof of intent, and motive. There is of course a way of doing so, as long as the attacker made a mistake. If they didn't, then it very well might be completely impossible to know who did it, and that's just how it is.

Timeframe, proof of intent, and motive are not what the commenter I replied to said, and they most certainly have those three pieces of information when attribution takes place generally speaking.

That's how I understood their comment, and in general, no, concordance of time frame and proof of intent are not proven. I think you underestimate the "proof" part of proof of intent. You not only have to prove conclusively that they did it, but back it up by proving that they intended to do so.

Re: FireEye Shares Details of Recent Cyber Attack

#247

Earlier quoted context omitted.

Timeframe, proof of intent, and motive are not what the commenter I replied to said, and they most certainly have those three pieces of information when attribution takes place generally speaking.

That's how I understood their comment, and in general, no, concordance of time frame and proof of intent are not proven. I think you underestimate the "proof" part of proof of intent. You not only have to prove conclusively that they did it, but back it up by proving that they intended to do so.

That's not a bar that's reached in the vast majority of criminal cases tried in the United States, or anywhere else for that matter, so it seems odd (approaching disingenuous) to try and establish that level of certainty here.

Re: FireEye Shares Details of Recent Cyber Attack

#248
post #214

Earlier quoted context omitted.

I'd counter with the following argument. I believe not a single cyber offensive op performed by a nation state had a budget of $1B. I'd say $1M is an upper bound here. Cyber warfare is used because it's cheap.

Spezialized custom work is expensive. I doubt Stuxnet cost only $1M. Licensing costs for law enforcement "remote access tools" (state trojans) can be millions (distributed among dozens of uses, but IMHO easy to see spending as much on a high-value single use). From the wiki article about the iPhone-encryption debate: "On April 7, 2016, FBI Director James Comey said that the tool used can only unlock an iPhone 5C like…

Yes, Stuxnet probably cost more. But Stuxnet was a higher level op, the target was also a nation state.

In this case they went after the tools to avoid detection and/or attribution in future ops. They could instead contract a company like their victim to develop such tools from scratch for about $10M.

Also, we're talking about nation states other than US.

Re: FireEye Shares Details of Recent Cyber Attack

#249

Earlier quoted context omitted.

That's how I understood their comment, and in general, no, concordance of time frame and proof of intent are not proven. I think you underestimate the "proof" part of proof of intent. You not only have to prove conclusively that they did it, but back it up by proving that they intended to do so.

That's not a bar that's reached in the vast majority of criminal cases tried in the United States, or anywhere else for that matter, so it seems odd (approaching disingenuous) to try and establish that level of certainty here.

If the American justice system doesn't attempt to prove that the person actually conclusively commited the crime and has mens rea as well as a motive and a congruent time-frame to commit it, then something is terribly wrong.

Re: FireEye Shares Details of Recent Cyber Attack

#250

Earlier quoted context omitted.

That's not a bar that's reached in the vast majority of criminal cases tried in the United States, or anywhere else for that matter, so it seems odd (approaching disingenuous) to try and establish that level of certainty here.

If the American justice system doesn't attempt to prove that the person actually conclusively commited the crime and has mens rea as well as a motive and a congruent time-frame to commit it, then something is terribly wrong.

> Documentation verifiably obtained from the attacker about the intent to attack, the methods used, the results and people involved.

Just to remind you where we started, as a contrast to the new goalposts you've established.

Post reply on HN