Earlier quoted context omitted.
Honestly, I'm shocked by this comment. As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market. SolarWind is fucked, they have a massive drop in new customers, I work with dozens of companies that are now plan to completely abandon their suites(those things take time). Insurance is a trap. once you read the small letters, they don't fully cover the damage, us…
If the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash. Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.
US companies hit by 'colossal' cyber-attack
241–250 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#242Earlier quoted context omitted.
Honestly, I'm shocked by this comment. As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market. SolarWind is fucked, they have a massive drop in new customers, I work with dozens of companies that are now plan to completely abandon their suites(those things take time). Insurance is a trap. once you read the small letters, they don't fully cover the damage, us…
If the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash. Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.
People short-squeezing stocks, shooting their "value" by 30x in 2 hours making them millionaires.
Hedge funds manipulating stocks to meet their portfolios
IPO's in billions of dollars for new, non-profitable startups just because of hype. when you look at the balance sheet it makes no sense.
The market is volatile and inflated, it is as clear as day. Whether there will be a crash? that's beyond my level.
Re: US companies hit by 'colossal' cyber-attack
#243One of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...
A cashless society is scary. Cash should always be an option and the inventory system should be disconnected from the internet.
Re: US companies hit by 'colossal' cyber-attack
#244Earlier quoted context omitted.
> this should be the death knell of these "remote monitoring and management" tools Yeah, sure. We should have a person on each of hundreds of sites whose only job is to check manually every router, switch, and vending machine. Maybe in the best HN traditions you will train the necessary workforce in a weekend?
Your quote cuts off before the salient part, and you seem to be attacking an imaginary argument. > tools that have extreme low-level access to networks and systems The emphasis being on the low level access. The solution is not having hundreds of people checking things by hand (though I'm sure that could contribute to security). The solution is more privilege separation; so that when the "remote monitoring tool" is c…
Having hundreds of people in each location whose only task is to do a boring monitoring an very occasional management tasks is a waste of your resources and their intelligence. We do automation to escape doing stuff that we can but which are to mind numbing. The illusion that every one of those hundreds of people will do their job to the necessary level of quality and without lapses of diligence is optimistic to say the least. Doing automation badly is not a reason not to do automation at all.
Re: US companies hit by 'colossal' cyber-attack
#245Depth can be provided by reverting to older skill sets. Fallbacks. Businesses should not go down because their computers locked up with ransomware.
I pitched and wrote some software for a company a few years ago to automate a very rigorous daily process that used to take a lot of man-hours. Occasionally, local networks would go down and people would have to revert to the old way of doing things on paper. But as turnover happened at the company, fewer and fewer people knew the "old way". Now they've reached a point where they're locally paralyzed if there's a network outage. They have to call in senior management on their day off to run the shop. I realized I didn't do them a favor. I solved one problem for them and saved them a lot of labor, but I created a whole new problem of reliance on a system that's more convenient, but much less robust than the paper system they used to have. And this doesn't even take into account the potential for security issues.
I think we should try somehow to architect things with offline fallbacks and training for those scenarios. The pace of attack is unsustainable and we're losing the war. If the point is to keep business running, we will lose the war if we lose the skill base and knowledge that we had which was capable of running the economy without a screen in front of them.
[edit] Come to think of it, there's a great startup idea in systematically re-paperizing businesses for failover. Take all that business logic that got written into software, and turn it back into a set of worksheets and training manuals.
Re: US companies hit by 'colossal' cyber-attack
#246I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
I suspect the attackers know this. Or else they aren't in it for the money. One or the other.
Re: US companies hit by 'colossal' cyber-attack
#247Earlier quoted context omitted.
That doesn't mean anything. in such a year their products should have flown off the shelves. Remote monitoring\management? in COVID year? just 3.5% that's horrendous
Are you sure about that? The customers who had experience with remote work and already knew that SW products would help them in this situation was a fixed number. The number of companies who had no clue about how to do remote work, and after haphazardly had to switch to it may still have no idea that you need to use products provided by SW. Also do you really need any of that to do remote work? Of course not.
More than anything, it proved that their model is flawed.
Just the number of gov agencies that are forced to stop working with them is a major blow.
Re: US companies hit by 'colossal' cyber-attack
#248After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…
It's not bonkers. We have 20-30 years of data on cyber attacks and Cybersecurity is not that important - https://ubiquity.acm.org/article.cfm?id=3333611 Larger the dumps get the harder they are to exploit or do serious damage. I can hand you all my orgs data and 200 people who work with it everyday and it will still take you years to figure out what anything means.
Ye what are you supposed to do with the information. I worked at a place that is paranoid for data leaks of non personal data, like source code.
Even if their direct competitor got the sources they would have almost no use for it since it is an undocumented mess. The source without the dev. departments is useless.
The same applies for business strategy if it leaks. Which competitor is nimble enought to change anything based on that data.
Re: US companies hit by 'colossal' cyber-attack
#249ION We may have underestimated the depth of the solarwind attack back in late last year.
Re: US companies hit by 'colossal' cyber-attack
#250Earlier quoted context omitted.
If we outlaw money no one will rob people don’t you know?
What would you rob from someone on the street, who isn't carrying any expensive item, especially no fungible ones? In the past, there were often abductions for ransom. This has mostly stopped, as the police always got the abductors when they tried to collect the money.