Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

21–30 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#21

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

I specifically have experience with Kaseya. I kicked and screamed to get us off of it, the IT people insisted it was top notch.

So when I became CFO I fired them (outside company), not just for this, but it didn’t help.

It’s bad software. 24/7 full low level access is exactly what it is. We had an add on that stored admin credentials in a JSON… so looking back on that, it seems this should have happened sooner.

Re: US companies hit by 'colossal' cyber-attack

#22
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

> Technical debt (also known as design debt or code debt, but can be also related to other technical endeavors) is a concept in software development that reflects the implied cost of additional rework caused by choosing an easy (limited) solution now instead of using a better approach that would take longer.

https://en.wikipedia.org/wiki/Technical_debt

Re: US companies hit by 'colossal' cyber-attack

#23
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

You know how you're working on a project, and everything mostly works but some stuff isn't quite up to spec, and you swear you'll fix it later because you have a lot of stuff to do? This is that, compounded over a few decades.

Re: US companies hit by 'colossal' cyber-attack

#24

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

It's not enough to just gain access - once you're in you need to compromise other defenses, you need to communicate your demand to the victim, you need to know how much to extort, you need to actually process the payment. Either you do this on a case by case basis or you take advantage of additional exploits that will only be viable for a subset of your potential targets, and this is all a race against time before someone notices your initial exploit. Either way, it's likely impractical for any non-nation state actor to simultaneously attack more than a few thousand targets in one go.

This is combined with a business model resembling patent trolls: you want to extort just a little less than is worth fighting for. If a company gets hit on its own, it's probably not in a position to really do anything about it, but if there is some major hack affecting tons of companies, the odds of an actor with significantly more tech capability like the US government getting involved go way up, and suddenly fighting seems like a good option.

Re: US companies hit by 'colossal' cyber-attack

#26

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Because there are plenty of zero-days the NSA can deploy if you step out of your lane.

It’s as much a political game at this point as anything.

If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves.

They’ll either end up hacked beyond their wildest imagination or facing literal hellfires.

It’s brinkmanship. When the devs literally die, they think twice.

Re: US companies hit by 'colossal' cyber-attack

#27
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

I was looking for a definition a few weeks ago and found the wikipedia article succinct and accurate (it met my needs anyway): https://en.wikipedia.org/wiki/Technical_debt

Re: US companies hit by 'colossal' cyber-attack

#28

Earlier quoted context omitted.

Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.

FWIW though (and I don't have easily available "sources") there was this immediate retaliation where Biden was like "we will completely prosecute these offenders" and within days DarkSide PR department said "Hey sorry we didn't mean to disrupt core services, we just want money" (sic) So it's a spectrum

That's not even close to what happened.

The administration left it alone for days saying they'll let private business sort it out. (Default investigation notwithstanding.)

When a bunch of news media started reporting the group was Russian and then insinuate it was a state sponsored attack, DarkSide said something along the lines of, "We didn't realize this would start geopolitical conflict. We will be careful to vet clients more carefully in the future."

Re: US companies hit by 'colossal' cyber-attack

#29

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

I think that the problem is these companies are publicly-traded. Chasing YoY returns and never having a down quarter are antithetical to building a lasting security model.
Post reply on HN