Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

231–240 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#231
post #95

Earlier quoted context omitted.

Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line. Sure, expenses rise a bit for a short period of time, but these are not catastrophic by any means. I mean, I'm looking at Solarwinds last earnings statement and comparing quarters from last year to now, they are up about 3.5% in re…

That doesn't mean anything. in such a year their products should have flown off the shelves. Remote monitoring\management? in COVID year? just 3.5% that's horrendous

Are you sure about that?

The customers who had experience with remote work and already knew that SW products would help them in this situation was a fixed number.

The number of companies who had no clue about how to do remote work, and after haphazardly had to switch to it may still have no idea that you need to use products provided by SW.

Also do you really need any of that to do remote work?

Of course not.

Re: US companies hit by 'colossal' cyber-attack

#232
post #64

Earlier quoted context omitted.

Cyber attacks nowadays demand their ransom payable in crypto.

If we outlaw money no one will rob people don’t you know?

What would you rob from someone on the street, who isn't carrying any expensive item, especially no fungible ones? In the past, there were often abductions for ransom. This has mostly stopped, as the police always got the abductors when they tried to collect the money.

Re: US companies hit by 'colossal' cyber-attack

#233

Earlier quoted context omitted.

That stuff is automated. What's not is managing big sums of money, turning crypto in to a more traditional currency/assets. That side of the operation probably has more people doing leg work than you'd think.

We really need someone from REvil to do an AMA on HN for this sort of detail. How did they get their first paying "customer"? What's their churn rate? Do they appreciate strong security measures, rendering each lost "sale" somewhat bittersweet? How are they handling the transition from developer-driven startup to a more mature organization?

More importantly, how long are they on Dogecoin? (Funny post, btw. The whole thing is totally absurd.)

Re: US companies hit by 'colossal' cyber-attack

#234

Earlier quoted context omitted.

Honestly, I'm shocked by this comment. As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market. SolarWind is fucked, they have a massive drop in new customers, I work with dozens of companies that are now plan to completely abandon their suites(those things take time). Insurance is a trap. once you read the small letters, they don't fully cover the damage, us…

If the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash. Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.

I've been hearing the "we're headed for a crash" thing with the same logic since at least mid-2019. Either we're not heading for a crash, or the market has become so irrational that it doesn't even matter any more, and we can build castles in the air forever.

Re: US companies hit by 'colossal' cyber-attack

#235
post #155
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

It's not bonkers. We have 20-30 years of data on cyber attacks and Cybersecurity is not that important - https://ubiquity.acm.org/article.cfm?id=3333611 Larger the dumps get the harder they are to exploit or do serious damage. I can hand you all my orgs data and 200 people who work with it everyday and it will still take you years to figure out what anything means.

We have operating systems for which remarkably few known exploits have ever been found.

VMS now "open" and recently running in a VM on Xeons.

I have always suspected that the silence that resounded suddenly about security prowess of VMS coincided with the release of extensive POSIX compatibility layers and the vaunted ports of years old open source nix wares as a excuse to play buzzword bingo at that time. But anyone writing a native VMS application I'd firmly embraced by a deep architecture designed to provide accounts for the time when DEC silicon and their own leading fab was creating a explosion in processing power and the number of users capable of being supported by a OS that has still incredibly well integrated system programming tool chain languages including Digital BASIC that can do about anything BLISS can low level. This virtually (sorry) made it a overnight imperative to get the security right and tight. Alpha had hardware security rings almost certainly to give VMS the chance to serve the maximum number of users and steal account wins.

Re: US companies hit by 'colossal' cyber-attack

#236
Russian state getting blamed for it in 3, 2, 1...

I don't want world War 3 over stupid ransomware because of bad sys admin work and some stupid criminal groups.

We should stop with this blaming. It is in Russia and other states interest to stop the ransom attacks even if they may be coming from some small group of people in their country. They have just as a hard time finding these criminals than we do finding them in the US.

Re: US companies hit by 'colossal' cyber-attack

#237

One of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...

A cashless society is scary. Cash should always be an option and the inventory system should be disconnected from the internet.

Re: US companies hit by 'colossal' cyber-attack

#238
post #234

Earlier quoted context omitted.

If the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash. Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.

I've been hearing the "we're headed for a crash" thing with the same logic since at least mid-2019. Either we're not heading for a crash, or the market has become so irrational that it doesn't even matter any more, and we can build castles in the air forever.

Mid-2019?

We can definitely build castles in the air for two years.

Re: US companies hit by 'colossal' cyber-attack

#239
post #218
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

> like fines and people going to jail for negligence Being bad at your job is not negligence, nor is underestimating the threat. It’d be nice to see consequences but I really don’t want to have the government locking people up for being well-paid fuck-ups. Don’t some of these companies have… shareholders?

People shouldn't go to prison for being fuck-ups.

Those negligently responsible should be fined and go to prison for leaking private data, endangering physical safety, possibly for compromising national security, damages from the toxic sludge they produce etc.

Note that the US does deploy it's national security forces to fix some of those fuck-ups, and at least threatens to use physical forces, so it's not just a private or civil matter.

Re: US companies hit by 'colossal' cyber-attack

#240

One of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...

Gee, cashless is such a great idea.

In related news, I saved money by replacing all my house's circuit breakers with old pennies.

Post reply on HN