Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

71–80 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#71
post #26

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Because there are plenty of zero-days the NSA can deploy if you step out of your lane. It’s as much a political game at this point as anything. If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves. They’ll either end up hacked beyond their wildest imagination or facing literal hellfires. It’s brinkmanship. When the devs literally die, they think…

At some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism.

Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker.

Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters didn't pay. There were no further attacks. The Teamsters declined to comment. (For those unfamiliar with American labor history, trying to push around the Teamsters Union usually ends badly for the pushers.)

[1] https://thehill.com/policy/cybersecurity/558066-teamsters-re...

Re: US companies hit by 'colossal' cyber-attack

#72
post #61

Earlier quoted context omitted.

I used to work for an MSP and we had used Kaseya. There was an AV integration, and then Kaseya changed to Kaspersky. I don’t remember what the prior AV software was. I always thought it bizarre we were actively installing AV software from Russia on banking and medical office PCs.

That has been a consideration in the AV software I recommend to friends, family, and professionally as an informal part of my threat assessment model. I viewed it as safer to buy products from anywhere other than someone that has ANY potential at all to go to war with the government of the country I live and work in. I really hope it never happens, but 'cold war' tensions might be waged with little cyber attacks and…

On the other hand… Kaspersky software isn’t shit. And I expect they catch a few things other US based companies might be incentivized or politely asked to look the other way on.

I wouldn’t run K, but I know from experience it’s actually effective.

Re: US companies hit by 'colossal' cyber-attack

#74
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

This isn't really true. Stock price is not an indicator of a company's "bottom line".

As someone who helps respond to major breaches at big companies, these types of breaches often result in enormous expenditures on company-wide efforts to close security gaps or revamp processes. Either a regulatory agency, or more often the company's board of directors, will make a mandate to the C-suite that something must be done. Some of these expenditure campaigns are low-visibility, some even to the employees of the company, and they are usually not very sexy or noteworthy, so you won't read about them on the front page of CNN but they do happen and they are very costly to the company (in the ballparks of tens to hundreds of millions of dollars).

I do think there should be harsher punishments in the form of fines, etc. But to say that there is "zero impact" just isn't true.

Re: US companies hit by 'colossal' cyber-attack

#75

Earlier quoted context omitted.

I specifically have experience with Kaseya. I kicked and screamed to get us off of it, the IT people insisted it was top notch. So when I became CFO I fired them (outside company), not just for this, but it didn’t help. It’s bad software. 24/7 full low level access is exactly what it is. We had an add on that stored admin credentials in a JSON… so looking back on that, it seems this should have happened sooner.

Did you think it was an unintentional technical liability, or did you think it was intentional?

Unintentional I think. If it was intentional I think things would have looked better on the surface.

Re: US companies hit by 'colossal' cyber-attack

#76
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

"tech debt" is when you decide that you will cut a corner to build something.

If you did it when building a plane, and it killed people, you would go to prison, but in the technology industry, this is acceptable as "the cost of being first"

Re: US companies hit by 'colossal' cyber-attack

#78
This really seems like a deliberate provocation testing the "16 sectors" considered off limits, delivered to Putin from the Biden Administration. And now waiting to see what the response is going to be, whether it was an indelible line or one drawn in sand.

I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware compromise to date.

Re: US companies hit by 'colossal' cyber-attack

#80
post #52

Earlier quoted context omitted.

I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)

These attacks didn't exist before crypto.

No, they typically sold stolen information on private/underground/invite forums or IRC.

Instead of crypto-randomware, it would be an all out worm or booter that would crush a service who would have to acquiesce to demands. Luckily, there weren't too many good services in existence, Cloudflare didnt exist, c10k was a mind blower, webdev was AJAX, XMLRPC, and CGI. The term TLS hadn't been coined, it was still called SSL, and nobody used it.

Instead of a money orders, they would trade trade calling cards, NEXON codes, gift cards, other stolen data like "fulls" or exploits or accounts for compromised infrastructure.

People would operate DDoS botnets for cash, spam you with V1@GRA ads from cracked boxes or hijacked relays, and the evergreen scam of fake RMAs. Let me know if "LOAD A PALLET OF CATALYST CHASSIS ONTO A BOAT OR ELSE ILL RELEASE YOUR SERIAL NUMBER DATABASE AND ALGORITHM ON MYSPACE" sounds scary or not.

The real difference is now we're 28 years into "Eternal September"[0], the whole planet is participating more or less. Cryptocurrency is possibly an enabler, but if it weren't that it would be Apple or Google Play codes. Just straight up exfil and sell.

In conclusion, these attacks didn't happen before Apple store or Google Play.

[0] - https://en.wikipedia.org/wiki/Eternal_September

Post reply on HN