Earlier quoted context omitted.
Growth for Google Workspace (previously G Suite) and Office 365 is insane. Office 365 has >258 million paid seats[0], while Google claims they have 2 billion paid seats (or "users")[1]. Soon enough more businesses will be using one of these than those that aren't (as in, those that are using Exchange or another email server). 0: https://office365itpros.com/2020/10/28/teams-115-million-use... . 1: https://www.axios.co…
Google claims 2 billion users across all their cloud services, not paid seats. For example, if you have a hangout and invite 20 people, that's 20 users. You don't have to be logged in to use a hangout link, so if you join another hangout later, and still aren't logged in, you're a new user.
U.S. Treasury breached by hackers backed by foreign government – sources
381–389 of 389 posts
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#382Earlier quoted context omitted.
You may not be aware, but Canada does have a sophisticated organization dedicated to electronic security: https://en.m.wikipedia.org/wiki/Communications_Security_Esta...
I'm Canadian and am well aware of CSE's existence. Do you think a Wiki article can capture the staggering incompetence that's endemic within the Canadian public sector?
Canada is leading the world in procuring the vaccine, and has had a very well-considered response to the pandemic. How long did it take for CERB cheques to arrive? Days? Look at the cluster that was the US response, even at the basic “get money in people’s hands” level.
Getting back to the original point - I’m sure there are a dozen or more countries with the capability to pull off something this sophisticated, which would include Canada. Highly unlikely that it was us, obviously.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#383All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…
This isn't going to help if the discussed is essentially tunneled through the Nat using legit protocols and traffic to the vulnerable service, where most of the attacks actually happen on the software side. How do you architect a firewall to accurately know if the application layer traffic is legit or not? It might not even be possible to fully implement something like this. Sounds complicated already. There is a rea…
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#384Earlier quoted context omitted.
I'm Canadian and am well aware of CSE's existence. Do you think a Wiki article can capture the staggering incompetence that's endemic within the Canadian public sector?
And you’re holding up the US public sector as your shining city on a hill? Canada is leading the world in procuring the vaccine, and has had a very well-considered response to the pandemic. How long did it take for CERB cheques to arrive? Days? Look at the cluster that was the US response, even at the basic “get money in people’s hands” level. Getting back to the original point - I’m sure there are a dozen or more co…
Certainly not. I'm only holding the US's cybersecurity complex as a shining city on the hill. Our government is so inept that I very much doubt CSE has the funding it needs or the ability to hire skilled people.
Happy to be proven wrong.
>Canada is leading the world in procuring the vaccine
Because we don't have any domestic production capacity due to decades of federal mismanagement. The same mismanagement that bought us used, obsolete fighter jets and submarines that catch fire at the slightest provocation. We lead the world in procuring those items too.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#385Earlier quoted context omitted.
I have seen a couple of corporate hacks (not publicized) who happened to be Russian groups hosted in Syria.... By state 'sponsored' it can mean many things, even if the countries just let them be and some officials get bribed to not do anything. In this case it was in Syria, which is a fundamental mess, but the fact that it was Russian groups and they have military presence there, it is enough to put it 'state sponso…
I’ve seen these things, including large DDoS attacks from both sides, black hat and white hat. I’ve also been recruited by Cyber Command, NSA, etc. The one thing that rings true is that governments and corporations vastly overestimate the capabilities of nation states, and vastly underestimate the capabilities of unaffiliated hacking groups and individuals. Most of the cutting edge InfoSec work is being done in OSS a…
FORBORNE PENDLETON PIEDMONT
They all seem to suggest some level of breakthrough with regards to cryptography, including public key cryptography.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#386Earlier quoted context omitted.
Ya, I think I consume far beyond the average for political news and had never heard of that distinction until now. I just always equated nation-state to country.
Why do you think people said 'nation-state' if you thought it meant the same as the shorter and simpler word 'country'?
But I could have been more specific that nation state tends to imply government of a country. Whereas country might include all citizens.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#387Earlier quoted context omitted.
Yes. Stuxnet being the most famous which brought this to more daylight -'cat out of the bag.' Trump admin also did a press push after changing policy to ramp up digital offense [1]. Notably these stories were obviously is coordinated and on purpose. e.g. not just someone leaker talking to reporter it was strategy. [1] https://www.nbcnews.com/politics/national-security/under-tru...
That push was actually interesting, since they were intentionally being open about their cyber capabilities. They also had a "press tour" about how they hacked ISIS [0]. There's clearly some mind games going on by showing your hand like that. [0] https://www.npr.org/2019/09/26/763545811/how-the-u-s-hacked-...
But that doesn't seem to stop Russia who doesn't give AF already under huge sanctions, or non-state groups like ISIS
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#388Earlier quoted context omitted.
To be clear, given that one never knows if or when a provider has been compromised... is the plan to just not update? What if they were compromised before you initially obtained the software? There's not much that can stop attacks like this. Preventing lateral movement, escalation, exfiltration, detection, and remediation, among other things, would be the way to go.
> There's not much that can stop attacks like this. Not giving people RCE on your machine will stop attacks like this.
Automatic updates are overall a huge net positive for security, despite this hack.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#389Earlier quoted context omitted.
Please leave your Redditor mentality at the door. Nothing good is gained by this kind of commenting.
So the person posting Russian State propaganda isn't the problem, I am for pointing out the uselessness of citing their work. Gotcha.