Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

171–180 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#172

I almost a fan of these attacks. At least someone is getting the bug bounty they deserve.

Attacks don't yield bug bounties, disclosures do. The only "bounty" is what the attacker exfils or ransoms.

The way bounty payouts seem so hit or miss (at least according to HN posts), the success rate and turnaround of ransoms looks a lot better.

Re: US companies hit by 'colossal' cyber-attack

#173

Earlier quoted context omitted.

Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.

Sounds so spooky, do say more! Do you mean Jason Bourne / John Wick shows up at the hackers’ nest?

Or Raytheon, yeah, I imagine so.

Re: US companies hit by 'colossal' cyber-attack

#174

Earlier quoted context omitted.

[flagged]

It's truly sad that this kind of rhetoric has made its way on to HN. What are you even talking about? Numbers to purchase food? Rounding up of people? Get a grip. We had a pandemic, like the countless others through history, and now we, the human race, are trying to fix it. You and your delusions are what stand in the way of that.

[flagged]

Re: US companies hit by 'colossal' cyber-attack

#175
post #137

Earlier quoted context omitted.

> You have no clue how businesses work if you seriously think that an additional, unexpected $400 million in expenses (almost 50% of their yearly net profits) "isn't a huge impact to them". That's really all that has to be said here. You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building…

>You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building burns down. I sit with CISOs daily discussing this stuff. $400m expenditures is enough to scare the shit out of them. A $400m building burning down would have CEOs fired (see: Equifax CEO being fired after breach). I don't know what…

Equifax’s stock is up 50% from a year ago. I’d say this hack did nothing bad for their stock.

Re: US companies hit by 'colossal' cyber-attack

#176

Earlier quoted context omitted.

It's truly sad that this kind of rhetoric has made its way on to HN. What are you even talking about? Numbers to purchase food? Rounding up of people? Get a grip. We had a pandemic, like the countless others through history, and now we, the human race, are trying to fix it. You and your delusions are what stand in the way of that.

[flagged]

I mean you're not even putting any efforts into your delusions. These are things that have been long debunked with very simple logic. My favorite part is how you believe that the big bad conspirators removed Trump and are pushing the vaccine, but back here in reality, Trump was the biggest champion of the vaccines. He created the program that got them into production so quickly. I don't know why I'm wasting the keystrokes here. It is clear from your blog that you are very far down the rabbit hole and are writing articles about things you have no understanding of.

Re: US companies hit by 'colossal' cyber-attack

#177

Theory: REvil is someone DARPA sent from the future to stop future cyber wars. Here's a list of popular Ransomware onions, REvils is called "Happy Blog" https://www.kiledjian.com/main/2021/3/4/popular-ransomware-d...

It's all just one person stuck in a loop. Predestination.

I think a college graduate with 2030's Metasploit probably would be enough to force the web to secure itself. A cynic might say 2021's Metasploit is enough.

It's hard to guess how big REvil would be. From their job ad -

"Teams that already have experience and skills in penetration testing, working with msf / cs / koadic, nas / tape, hyper-v and analogues of the listed software and devices.

Re: US companies hit by 'colossal' cyber-attack

#178

It's amazing that the World Economic Forum was able to predict a global pandemic in 2019 with Event 201 [1] and widespread cyber attacks in 2021 with Cyber Polygon [2]. Their timing for conducting these trainings is impeccable. We'll probably need Internet Passports, with malware scan certificates, to get online safely. Hope you're not an anti-scanner (it's totally secure). Evil Russian hackers will be a convenient s…

[flagged]

> I have a feeling people who don’t get the vaccine are going to end up in camps. I know that’s already true in some countries.

That is a lie. In no country that is happening.

I mean, everything you said is a lie, but don't have more time to waste with "arguments" like yours, just wanted to make sure everyone else here knows that that baseless claim in particular is a lie.

Re: US companies hit by 'colossal' cyber-attack

#179

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

One could hope but I doubt it. CFO's gonna CFO and it's "cheaper" to outsource IT. I had one of these vendors really pushing me to "take a call" or "let them show me how they could cut costs". It was ALL about the costs. And I eventually called the CEO and said we would consider it if the company would take out a $100M bond that we could call on to repair any damage that occurred as a result of their managing our IT…

The CEO and CFO are right because this notion of reducing "attack surface" is not static. It changes from day to day and no technologist can guarantee what changes they add today makes any difference tomorrow. The promise is False. Therefore the principle of least action is justified.

Re: US companies hit by 'colossal' cyber-attack

#180
I worked for an MSP that used Kaseya VSA. First used the SaaS version. Their "SSO" is not claims-based but an agent that may just run on a DC and copy NTLM hashes to the SaaS instance. Had an admin account compromised. Asked for logs from Kaseya. Attacker traffic came from a Tor exit node. They did zero ingress filtering. Much of their codebase is Classic ASP riddled with comments like "'fixed SQL injection." Beyond the bizarre HTTP traffic, the agent communication protocol is a black box with some VNC. Logging goes to SQL so you have to do custom work to parse or push that to a SIEM. Terrified. Moved to on-prem and stuck a bunch of mitigating controls (blocking known Tor exit nodes, blocking egregious injection attempts, etc.). Wrote custom scripts to ingest logs. I'd like to see a professional penetration test report against their software. It does not look good.
Post reply on HN