Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

51–60 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#52

I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.

I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these?

Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)

Re: US companies hit by 'colossal' cyber-attack

#54

Earlier quoted context omitted.

FWIW though (and I don't have easily available "sources") there was this immediate retaliation where Biden was like "we will completely prosecute these offenders" and within days DarkSide PR department said "Hey sorry we didn't mean to disrupt core services, we just want money" (sic) So it's a spectrum

That's not even close to what happened. The administration left it alone for days saying they'll let private business sort it out. (Default investigation notwithstanding.) When a bunch of news media started reporting the group was Russian and then insinuate it was a state sponsored attack, DarkSide said something along the lines of, "We didn't realize this would start geopolitical conflict. We will be careful to vet…

Did they leave it alone for days? The FBI seized the ransom (claiming it was left in a Coinbase account) so clearly someone was doing something.

Re: US companies hit by 'colossal' cyber-attack

#55

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

I think that the problem is these companies are publicly-traded. Chasing YoY returns and never having a down quarter are antithetical to building a lasting security model.

Microsoft, Apple, and Google seem to be doing ok.

Re: US companies hit by 'colossal' cyber-attack

#56

I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.

Without crypto, would it be impossible to extract cash from a company? What is the current mechanism used to get funds that the FBI can’t track down? Wire the money to a jurisdiction mostly out of our sphere of influence.

Re: US companies hit by 'colossal' cyber-attack

#57
post #49

The Microsoft team at a company I used to work for tried to push this very software out onto all staff machines. Our Platform Engineering team managed to push back on it based on the grounds that it was a serious security concern and is essentially an "enterprise" backdoor. The following year the bulk of our team decided to resign move on to other employment - I was told Kaseya was rolled out to all machines shortly…

Ah but things like "security feel good feelings", being "in the cloud" and kickbacks are more important for the higher-ups in certain companies.

And of course, it's hard to believe the (upstream) companies responsible for these weak security practices will suffer any consequences

Re: US companies hit by 'colossal' cyber-attack

#58
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

You're patching over problems with short term solutions instead of investing the time and effort to fix it "the right way".

Like when you need to fix all the support columns in your building, but instead of spending millions to take them down one at a time and replace the corroding rebar inside, you just patch over the exterior cracks. They will look fine from the outside and get the job done on a day to day basis, but they hide structural problems and one day that debt will come due. Most of the time it's in the form of a giant project to finally fix everything, but sometimes it's catastrophic failure.

Re: US companies hit by 'colossal' cyber-attack

#59
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

its like not combing or washing your hair to save time but it ends up turning into dreadlocks and then it still kinda serves as hair but is much harder to work with and untangle into other hairstyles.

"Softhwair", if you will :D.

Post reply on HN