Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

41–50 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#41
post #40

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

I know we're still pretty close to the Ubiquiti breach, but since then, they've added 2FA. Is your opinion of their products the same?

Ubiquity introduced new vulns while fixing that fiasco from last year: https://www.zerodayinitiative.com/blog/2021/5/24/cve-2021-22...

On the other hand, all of the other networking HW sucks just as much. E.g. here are Netgear vulnerabilities published just this week: https://www.microsoft.com/security/blog/2021/06/30/microsoft...

Re: US companies hit by 'colossal' cyber-attack

#42

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.

Sounds so spooky, do say more! Do you mean Jason Bourne / John Wick shows up at the hackers’ nest?

Re: US companies hit by 'colossal' cyber-attack

#43

These digital networks and devices have become so complex we can’t reason about them, or in any case can’t easily reason about them given the resources available to most of the organizations running them. However, from what I’ve seen, most of these attacks are successful because these organizations are simply neglecting best practices (e.g. patch management, whitelisting, security awareness training).

like everything else in america, #1 priority is fèeding ceo salary and shareholder value. everything in corporate america is derived from the growing wealth inequality and these shake downs are precisely targetting the glut. soon enough, itll still be cheaper to have a bribe fund, just like tax evasion lawyers, lobbiests and the rest of the feeder classes than a holisitic defense.

This is a tiresome, meaningless religious mantra nowadays.

Yes there is corruption. No not everybody is corrupt. No it does not only exist in USA nor is USA anywhere near the worst. No you can't blame anything and everything you don't like on corruption and greed.

Re: US companies hit by 'colossal' cyber-attack

#44

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

> The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more!

If it was me (it was not), I’d use it to gain persistance in companies like Kaseya, extending my beachhead as first priority. After that is basically game over, cleaning it would take making new IT systems from scratch. And lets not forget firmware…

Re: US companies hit by 'colossal' cyber-attack

#45

Earlier quoted context omitted.

Would you mind briefly explaining the concept of "tech debt" to a layperson?

> Technical debt (also known as design debt or code debt, but can be also related to other technical endeavors) is a concept in software development that reflects the implied cost of additional rework caused by choosing an easy (limited) solution now instead of using a better approach that would take longer. https://en.wikipedia.org/wiki/Technical_debt

I don't think it's just rework, it's also any other future risks or difficulties implied by taking the easy way for now.

I should just edit the wikipedia page, but they won't accept edits from my current IP address.

Re: US companies hit by 'colossal' cyber-attack

#47
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

First we have to ask, "why does programming get harder as the project goes on?"

Let's say you are designing a system - any kind of system - with the philosophy that everything should be connected to everything else. Your first part goes in quick with no connections. Your second part goes in quick and has one connection. Your third part has to be connected in two places for it to work right, but that's not a problem. Your hundredth part has to be connected in a ninety nine places for it to work right, and now you're spending more time wiring than you are on making parts.

Then we ask, "what can we do when that happens?"

You have to put effort into the design of the system, reassigning duties and studying the nature of the problem it's solving, so that you lay down the connections along the true contours of the map, and not between every single component. Afterwards the next component you add has to be connected only to the three other things it's actually related to and you're back in business. This results in a period of time with no new features or even bugfixes, but afterwards you move faster.

Then we ask, "why do people call it debt?"

Because you pay interest on it when you have it, you run it up when you're short, and you better have a plan to pay it down or else you will go out of business.

Re: US companies hit by 'colossal' cyber-attack

#48

Earlier quoted context omitted.

like everything else in america, #1 priority is fèeding ceo salary and shareholder value. everything in corporate america is derived from the growing wealth inequality and these shake downs are precisely targetting the glut. soon enough, itll still be cheaper to have a bribe fund, just like tax evasion lawyers, lobbiests and the rest of the feeder classes than a holisitic defense.

This is a tiresome, meaningless religious mantra nowadays. Yes there is corruption. No not everybody is corrupt. No it does not only exist in USA nor is USA anywhere near the worst. No you can't blame anything and everything you don't like on corruption and greed.

[deleted]

Re: US companies hit by 'colossal' cyber-attack

#49
The Microsoft team at a company I used to work for tried to push this very software out onto all staff machines.

Our Platform Engineering team managed to push back on it based on the grounds that it was a serious security concern and is essentially an "enterprise" backdoor.

The following year the bulk of our team decided to resign move on to other employment - I was told Kaseya was rolled out to all machines shortly after.

Companies need to ensure that risks raised by senior engineering teams are taken into account before deploying company wide software.

Re: US companies hit by 'colossal' cyber-attack

#50

These digital networks and devices have become so complex we can’t reason about them, or in any case can’t easily reason about them given the resources available to most of the organizations running them. However, from what I’ve seen, most of these attacks are successful because these organizations are simply neglecting best practices (e.g. patch management, whitelisting, security awareness training).

like everything else in america, #1 priority is fèeding ceo salary and shareholder value. everything in corporate america is derived from the growing wealth inequality and these shake downs are precisely targetting the glut. soon enough, itll still be cheaper to have a bribe fund, just like tax evasion lawyers, lobbiests and the rest of the feeder classes than a holisitic defense.

Such a brave meme. It might carry some water if the same problem didn’t apply to every country with both open and closed source projects.
Post reply on HN