Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

201–210 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#201

Earlier quoted context omitted.

“After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.” It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after th…

Isn't Equifax a government organization? How do they have severance packages?

It's a para-state agency; while Americans don't have ID cards because they're afraid of surveillance, a private company having a complete database of everyone and veto power over mortgages is fine because it's a private company.

Re: US companies hit by 'colossal' cyber-attack

#202
post #113
post #65

Earlier quoted context omitted.

Toothpaste's out of the tube. Banning the exchanges won't stop the ransomware.

Why not? What's to prevent e.g. the U.S. Government from outlawing the use of exchanges, and/or outlawing the payment of cryptocurrency ransoms, just as it forbids globally the payment of bribes?

[deleted]

Re: US companies hit by 'colossal' cyber-attack

#203

“ At a summit in Geneva last month, US President Joe Biden said he told Russian President Vladimir Putin he had a responsibility to rein in such cyber-attacks.” I don’t understand how Putin can stop these attacks unless he is personally responsible for them. Imagine someone in the US hacking systems in Russia or China. How in the hell Biden would know who did that and stop them? The naivety of US government is just a…

If we, the west, let Russia take Crimea and China take Hong Kong with minimal fuss, I don't see why a few cyber attacks would get more attention.

Take over? I thought Hong Kong was given back?

Re: US companies hit by 'colossal' cyber-attack

#204

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

It made my life as an MSP easier for sure and allowed us to support more clients and bigger businesses and get more done. But I fear you might be right, and it just isn’t worth the risk of a hole like this. Now I’m going to be up for days restoring servers, and data on any workstations that wasn’t backed up is gone. I think we’ll be filing a claim for this one.

Re: US companies hit by 'colossal' cyber-attack

#205

Earlier quoted context omitted.

Would you mind briefly explaining the concept of "tech debt" to a layperson?

> Technical debt (also known as design debt or code debt, but can be also related to other technical endeavors) is a concept in software development that reflects the implied cost of additional rework caused by choosing an easy (limited) solution now instead of using a better approach that would take longer. https://en.wikipedia.org/wiki/Technical_debt

This is it. It's not just "stuff that's not perfect". The term technical debt refers to things the business accepts as debt to be repaid later for more as the price of getting a feature out of the door sooner.

Re: US companies hit by 'colossal' cyber-attack

#206

Earlier quoted context omitted.

Would you mind briefly explaining the concept of "tech debt" to a layperson?

I presume you were not trying to be ironic with this request (given how you chose the easy option of inconveniencing others rather than Google/Wikipedia) Anyway, here's a good introduction: https://en.m.wikipedia.org/wiki/Technical_debt

Or, maybe they thought someone on HN would be able to explain it better than the Wikipedia article. It did not seem like an unreasonable request to me at all.

Re: US companies hit by 'colossal' cyber-attack

#207

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

If i recall correctly solarwinds was more of an espionage operation by russia government actors. Their targets were mainly government agencies in US. The ransomware attack are from private profit-seeking groups, although I remember the head of REvil tweeted once he was neighbours with KGB's number two guy so you could argue the distinction is vague

Attribution is quite hard. When the 3-letter-agency tools leaked a few years ago, one of their leaked tools concerned deliberate false attribution.

The solarwinds attack seemed to be about using a supply-chain attack to gain persistent access for recon and lateral movement. Pivot to Azure via Microsoft via SolarWinds software. Whomever it was tried to stay invisible for as long as possible. Once the game was up, they were not so careful about visible actions.

RansomWare is more smash and grab though it's interesting/sad to see the current trends of Supply Chain attack prevalence and Ransomware attacks converge.

Re: US companies hit by 'colossal' cyber-attack

#208
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

“After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.” It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after th…

It's almost as if making shareholder returns and CEO pay the only indicator of company success creates terrible consequences.

Re: US companies hit by 'colossal' cyber-attack

#209
post #167

Earlier quoted context omitted.

One could hope but I doubt it. CFO's gonna CFO and it's "cheaper" to outsource IT. I had one of these vendors really pushing me to "take a call" or "let them show me how they could cut costs". It was ALL about the costs. And I eventually called the CEO and said we would consider it if the company would take out a $100M bond that we could call on to repair any damage that occurred as a result of their managing our IT…

I keep reading over and over again indignant comments about "cost centers" on Hacker News and I think it's not a good term to use because I looked up the definitions and the only logical consensus I could find is that everything which isn't shareholder profit is a cost center. It's just rhetoric.

I don't think it is - I think it's cultural and organisational. The CFO and Finance in general see businesses as capital flows, they don't see value being added - just opportunities for leverage and cash management. The description of a cost center is a labelling denoting a target for removal and reduction - the destruction of value that occurs (typically 12 -24 months after the exercise) is seen as disconnected and irrelevant.

Re: US companies hit by 'colossal' cyber-attack

#210

One of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...

[deleted]
Post reply on HN