Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

261–270 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#261
post #71
post #26

Earlier quoted context omitted.

Because there are plenty of zero-days the NSA can deploy if you step out of your lane. It’s as much a political game at this point as anything. If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves. They’ll either end up hacked beyond their wildest imagination or facing literal hellfires. It’s brinkmanship. When the devs literally die, they think…

At some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism. Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker. Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters…

Given that paying the ransom only outs yourself as a potential repeated target who pays, it was a wise decision

Source: https://searchsecurity.techtarget.com/news/252502519/Repeat-...

Re: US companies hit by 'colossal' cyber-attack

#262

Oddly explosive headline, considering: > It is not clear what specific companies have been affected - a Kaseya representative contacted by the BBC declined to give details. So why "colossal"? > "This is a colossal and devastating supply chain attack," Huntress Labs' senior security researcher John Hammond said in an email to Reuters news agency. The BBC is going with "colossal" in their headline simply because the gu…

Hacker News hit by "oddly explosive" BBC headline.

Beautifully executed.

Re: US companies hit by 'colossal' cyber-attack

#264

Earlier quoted context omitted.

This is a tiresome, meaningless religious mantra nowadays. Yes there is corruption. No not everybody is corrupt. No it does not only exist in USA nor is USA anywhere near the worst. No you can't blame anything and everything you don't like on corruption and greed.

Perhaps, but of all the leading developed nations on Earth, the US has a particularly corrupt government that sells itself to the highest bidder thanks to Citizens United and armies of lobbyists. Our healthcare, prison, and student loan systems, for example, prey on US citizens without repercussions at lengths that don’t fly in most developed countries. I think it’s safe to say that corruption and greed are at the ro…

Market capitalism is greedy and brutal, but the discussion here is about ransomware, which is one of the things the market should be well equipped to solve. Rather than throwing broad shade at the system in general, consider the opportunity here. Faced with a threat to the increasing automation they rely on for YoY growth, corporations could react by ensuring better job security and higher pay, better workplace conditions and better training, to create more resilience. The market could support those shifts if they see the danger of relying totally on non-human decision making at the local level. The Russians might even be doing us a favor if we're adaptable enough to take advantage of what we're learning from it.

Re: US companies hit by 'colossal' cyber-attack

#265
> The source of these indicators are auto-emailed Kaseya VSA Security Notifications indicated the "KElevated######" (SQL User) account performed this action. We're hesitant to jump to any conclusions, but this could via suggest execution via SQL commands.

Some form of remote, unauthenticated SQL injection then?

1. https://www.reddit.com/r/msp/comments/ocggbv/comment/h3u5j2e

Re: US companies hit by 'colossal' cyber-attack

#266
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

There's 3 people.

1. Knows the wider requirements but isn't involved in the implementation. They can't fully specify what's needed without doing the actual implementation; the map is not the territory.

2. Is told the broad requirements but probably can't grasp the things they aren't told in the imperfect spec. So under time pressure, in good faith, they do the simplest workaround possible.

3. Is given the next set of requirements. Instead of re-engineering the original design, under time pressure and in good faith, they add a workaround for the workaround.

Each new workaround is "tech debt".

When you add the next feature you now have to deal with multiple levels of complexity not in the original spec.

Understanding the actual implementation now takes more time than expected. The chances are that no one fully does, which leads to further mistakes and workarounds. So more tech debt.

Either you pay the debt down and re-engineer or you pay the compounding interest forever.

...and so on. Each new level of complexity gets harder and harder to understand and debug because no one really knows how the real design, held in the actual works.

Re: US companies hit by 'colossal' cyber-attack

#267
post #265

> The source of these indicators are auto-emailed Kaseya VSA Security Notifications indicated the "KElevated######" (SQL User) account performed this action. We're hesitant to jump to any conclusions, but this could via suggest execution via SQL commands. Some form of remote, unauthenticated SQL injection then? 1. https://www.reddit.com/r/msp/comments/ocggbv/comment/h3u5j2e

Some of those comments are straight up nightmare fuel for sysadmins

> We are severly fucked. Up to 2100 endpoints are infected right now, most are desktops but also servers.

> We have been hit as well 1000 endpoints. What is your plan of restoration?

Happy 4th of July weekend everyone.

Re: US companies hit by 'colossal' cyber-attack

#268
post #218

Earlier quoted context omitted.

> like fines and people going to jail for negligence Being bad at your job is not negligence, nor is underestimating the threat. It’d be nice to see consequences but I really don’t want to have the government locking people up for being well-paid fuck-ups. Don’t some of these companies have… shareholders?

> I really don’t want to have the government locking people up for being well-paid fuck-ups. If you go to a doctor and he fucks up: he (or his insurer) has to pay you. If he really fucks up, he ceases to be able to practice medicine. The same with nurses, lawyers, accountants, architects and other professionals. Software's much better—then they point to the "we take no liability for any errors" clause in the contract…

afaik if a doctor fucks up his rights to practice medicine are taken away by a board of (probably) doctors after a examination of the case. Although this sounds all well and good, I've read countless accounts of this not happening as much as it should be happening, almost similar to the police not taking action on their own officials who go bad, corruption runs deep in our systems and imo our psyche

I think a top down approach to enforce anything at scale is never gonna work until people decide to respect their place in the world and do the due diligence from bottom up

Re: US companies hit by 'colossal' cyber-attack

#269
post #52

Earlier quoted context omitted.

I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)

That's an accurate interpretation of what I'm saying. I don't think it's particularly bold. I don't have any hard evidence but I'm sure you could find some. I certainly don't remember ransomware attacks being very prevalent prior to last decade. They all seem to request cryptocurrencies (I can tell you're a coin head because you refer to them simply as crypto). Without cryptocurrencies ransomeware would largely go aw…

Extortion have been around for ages. There have been many payment methods used for it on the Internet. Prepaid credit cards, expensive phone numbers, gift cards, mobile refills, cash to private post boxes, bank accounts in sketchy countries and so on. But sure, cryptocurrencies makes it easier.

Re: US companies hit by 'colossal' cyber-attack

#270

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

"Centralized hosting and management (SaaS, PaaS model) has the advantage of security at scale."

it follows that

"Centralized hosting and management (SaaS, PaaS model) has the advantage of insecurity at scale."

Post reply on HN