Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

221–230 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#221
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

Honestly, I'm shocked by this comment. As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market. SolarWind is fucked, they have a massive drop in new customers, I work with dozens of companies that are now plan to completely abandon their suites(those things take time). Insurance is a trap. once you read the small letters, they don't fully cover the damage, us…

If the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash.

Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.

Re: US companies hit by 'colossal' cyber-attack

#222
post #201

Earlier quoted context omitted.

Isn't Equifax a government organization? How do they have severance packages?

It's a para-state agency; while Americans don't have ID cards because they're afraid of surveillance, a private company having a complete database of everyone and veto power over mortgages is fine because it's a private company.

There's three companies doing it, so they possess the holy blessings of the all-knowing market \s

Re: US companies hit by 'colossal' cyber-attack

#223
post #218
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

> like fines and people going to jail for negligence Being bad at your job is not negligence, nor is underestimating the threat. It’d be nice to see consequences but I really don’t want to have the government locking people up for being well-paid fuck-ups. Don’t some of these companies have… shareholders?

If you screw it up with a building or a bridge, you might go to jail, and we as a society are fine with that. Why not in this case as well?

Re: US companies hit by 'colossal' cyber-attack

#225
post #113

Earlier quoted context omitted.

Why not? What's to prevent e.g. the U.S. Government from outlawing the use of exchanges, and/or outlawing the payment of cryptocurrency ransoms, just as it forbids globally the payment of bribes?

Nothing. Also nothing prevents the US government from outlawing drugs. Likely with the same effectiveness. BTW are most of these hackers transferring to fiat through U.S. exchanges? I can't imagine that's the case but maybe it is.

It’s not about stopping the hackers from accessing the exchange, it’s about preventing businesses from being able to pay ransoms.

Re: US companies hit by 'colossal' cyber-attack

#226

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

Just a month or so after the attacks, one of our large government clients signed up to no less than three such vendors and deployed their products to almost all of their production servers.

I discussed this with their security team leads, and they answered with a straight face that it's okay because they had to spend their budget before the end of the financial year.

Re: US companies hit by 'colossal' cyber-attack

#227
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

UK companies act hundreds of summary criminal offenses covering all aspects of corporate responsibility for any director.

A 1977 case precedent established in the event that a director relies upon the advice of a accountant for making company directions, he or she will be liable to be banned from holding a directorship for life. The appeal failed. This is because the only essential role of a director is to be themselves a competent assessor of the company affairs.

If you can't knobble the board of a UK limited liability company for letting go their own primary competitive asset (the more important consideration for the law designed to govern the behaviour of directors in fulfilling two goals : justify public indemnity to the extent of any shares they own in the company in the event of collapse ; and do their job without prejudice to the shareholders or the crown treasurer to pay negligence.

Summary criminal charges are convicted on bringing proof and a judge not being shown disproof. Criminal intent doesn't come into it.

Re: US companies hit by 'colossal' cyber-attack

#228

Earlier quoted context omitted.

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

Can you explain more about the ‘root ash’ issue please?

By using some of these tools they are under the false assumption that things that are otherwise considered security threats are somehow okay because for example the tool rotates passwords for you. It gives a false sense of security and allows you to do things that would otherwise be considered security threats.

It's as if someone sells you a laser that shoots intruders and tells you, you can leave the front door open from now on, but that laser only works 1 in 3 times.

Re: US companies hit by 'colossal' cyber-attack

#229
post #218
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

> like fines and people going to jail for negligence Being bad at your job is not negligence, nor is underestimating the threat. It’d be nice to see consequences but I really don’t want to have the government locking people up for being well-paid fuck-ups. Don’t some of these companies have… shareholders?

> I really don’t want to have the government locking people up for being well-paid fuck-ups.

If you go to a doctor and he fucks up: he (or his insurer) has to pay you. If he really fucks up, he ceases to be able to practice medicine.

The same with nurses, lawyers, accountants, architects and other professionals.

Software's much better—then they point to the "we take no liability for any errors" clause in the contract and everyone carries on as if nothing ever happened.

Post reply on HN