Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

61–70 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#61

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

I used to work for an MSP and we had used Kaseya. There was an AV integration, and then Kaseya changed to Kaspersky. I don’t remember what the prior AV software was. I always thought it bizarre we were actively installing AV software from Russia on banking and medical office PCs.

That has been a consideration in the AV software I recommend to friends, family, and professionally as an informal part of my threat assessment model.

I viewed it as safer to buy products from anywhere other than someone that has ANY potential at all to go to war with the government of the country I live and work in. I really hope it never happens, but 'cold war' tensions might be waged with little cyber attacks and that software came to mind as a risk.

Re: US companies hit by 'colossal' cyber-attack

#62

I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.

Without crypto, would it be impossible to extract cash from a company? What is the current mechanism used to get funds that the FBI can’t track down? Wire the money to a jurisdiction mostly out of our sphere of influence.

Wire transfers themselves are straightforward to track, due to something called SWIFT. That’s one reason “money laundering” is a thing: it exists to obfuscate the trail of the money being traced.

Re: US companies hit by 'colossal' cyber-attack

#63
post #52

I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.

I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)

These attacks didn't exist before crypto.

Re: US companies hit by 'colossal' cyber-attack

#64

I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.

What does this have to do with cryptocurrencies?

Cyber attacks nowadays demand their ransom payable in crypto.

Re: US companies hit by 'colossal' cyber-attack

#66

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

I specifically have experience with Kaseya. I kicked and screamed to get us off of it, the IT people insisted it was top notch. So when I became CFO I fired them (outside company), not just for this, but it didn’t help. It’s bad software. 24/7 full low level access is exactly what it is. We had an add on that stored admin credentials in a JSON… so looking back on that, it seems this should have happened sooner.

Did you think it was an unintentional technical liability, or did you think it was intentional?

Re: US companies hit by 'colossal' cyber-attack

#67
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

Two ways, I think they're easy to understand but I have no experience in teaching:

Technical debt is like not cleaning your house to save a bit of time everyday. When you actually have to clean it, it's going to take longer than the time you saved. And until it's not clean, everything you do will be a bit worse because the house isn't clean.

"Remember when you were a student and didn't do the dishes, and then when you finally did them everything was dry and sticky and stinky, and it took you a lot of time to wash everything and you felt terrible? That's dishes debt. Technical debt is the same. When you make a change, you produce dirt in the codebase, and if you don't or can't take the time to clean every time, dirt accumulates."

Re: US companies hit by 'colossal' cyber-attack

#68
After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.

You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for one of the most impactful cyber incidents yet. Hell, if you invested in January, after most of the stuff blew over, you would be up nearly 20% on your investment.

There is even a perverse incentive to not do things and just get cyber insurance to cover you. Since these underwriters generally have no fucking clue what they are doing, you can actually make money on a cyber intrusion if you play your cards right. Only now that insurance companies have paid out the nose with ransomware incidents have they started to wise up. Having worked in the space, its absolutely bonkers what we accept as normal business practices with regards to cybersecurity.

Re: US companies hit by 'colossal' cyber-attack

#69
post #49

The Microsoft team at a company I used to work for tried to push this very software out onto all staff machines. Our Platform Engineering team managed to push back on it based on the grounds that it was a serious security concern and is essentially an "enterprise" backdoor. The following year the bulk of our team decided to resign move on to other employment - I was told Kaseya was rolled out to all machines shortly…

What software are you referring to? The article only mentions "VSA tool", and that does not ddg well.

Re: US companies hit by 'colossal' cyber-attack

#70
post #5

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

You'd need to be able to process all the orders also. Every company needs support to pay the random and unlock. Also, at some point the military gets involved.

Correct, this won't get better until these groups are physically disbanded.
Post reply on HN