Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

271–280 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#271

Earlier quoted context omitted.

[flagged]

I mean you're not even putting any efforts into your delusions. These are things that have been long debunked with very simple logic. My favorite part is how you believe that the big bad conspirators removed Trump and are pushing the vaccine, but back here in reality, Trump was the biggest champion of the vaccines. He created the program that got them into production so quickly. I don't know why I'm wasting the keyst…

The answer to the question “do crazy people know they are crazy” is a firm “absolutely not” and the comment you’re replying to proves that.

Don’t bother replying, it’s always the same. If they reply at all it will be with a mix of half-truth personal anecdotes, scientific-sounding nonsense, paranoid delusions and if you’re really unlucky outright antisemitism.

They are far gone and they don’t know it yet, there isn’t much you can do to stop that purely online.

Just feel sorry, move on, and petition your representatives to tackle the mental health crisis befalling many of us.

Re: US companies hit by 'colossal' cyber-attack

#272
Slightly tangential but relevant to people who are interested in how some nations are now sponsoring cyber attacks

( Not saying this "colossal" one was state sponsored :-) )

"The Lazarus heist: How North Korea almost pulled off a billion-dollar hack" [0]

[0] https://www.bbc.com/news/stories-57520169

Re: US companies hit by 'colossal' cyber-attack

#273

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

I have never understood this; the whole Enterprise™ security business talks about all these things where half the time I literally don't even know what they're on about. They all seem to take it very serious; great! And at the same time they miss basic stuff like, I don't know, subscribing to Apache struct release mailing list. Or not keeping employee credentials around on public servers used to file credit disputes. Or in the case of Solarwinds not using "solarwinds123" as a password (probably not used in the hack, but still).

None of this is rocket science and these people probably aren't stupid, so somehow, somewhere, something is going horribly systemically wrong (incentives? Training? Organisation? I don't know).

Re: US companies hit by 'colossal' cyber-attack

#274

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

Just a month or so after the attacks, one of our large government clients signed up to no less than three such vendors and deployed their products to almost all of their production servers. I discussed this with their security team leads, and they answered with a straight face that it's okay because they had to spend their budget before the end of the financial year.

This entire "we need to spend our budget"-attitude is something I will never understand. So what if you get less money next year? Firstly, it's not going in your pocket, and secondly clearly you can get by just fine with a lower budget.

And everyone knows this is how it works too – so the Powers That Be keep setting the wrong incentives too.

This is why I never worked for a large Enterprise company or government agency. I'd go crazy.

Re: US companies hit by 'colossal' cyber-attack

#275
post #69
post #49

The Microsoft team at a company I used to work for tried to push this very software out onto all staff machines. Our Platform Engineering team managed to push back on it based on the grounds that it was a serious security concern and is essentially an "enterprise" backdoor. The following year the bulk of our team decided to resign move on to other employment - I was told Kaseya was rolled out to all machines shortly…

What software are you referring to? The article only mentions "VSA tool", and that does not ddg well.

[deleted]

Re: US companies hit by 'colossal' cyber-attack

#276
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

Hell, if you invested in January, after most of the stuff blew over, you would be up nearly 20% on your investment.

Yeap, I did that with Ubiquity after their incident. Bought at $275 and the stock now is 12% higher. Seems like a good strategy, and I'm looking forward for similar incidents in the future.

Re: US companies hit by 'colossal' cyber-attack

#277
post #234

Earlier quoted context omitted.

If the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash. Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.

I've been hearing the "we're headed for a crash" thing with the same logic since at least mid-2019. Either we're not heading for a crash, or the market has become so irrational that it doesn't even matter any more, and we can build castles in the air forever.

I believe the market should in theory rise with inflation. Doesn't seem too crazy all things considered.

Re: US companies hit by 'colossal' cyber-attack

#278

Earlier quoted context omitted.

If the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash. Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.

Isn't inflation above gains essentially a devaluing of the market? If the stock market goes slightly down and inflation ramps up significantly isn't that the same as a crash?

The most expensive and valued stocks are "essentials" they dann just increase there price with inflation.

I dont understand the problem with inflation..

Re: US companies hit by 'colossal' cyber-attack

#279

I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.

Ransomware is not an innovation that came as a result of cryptocurrency, it was just accelerated by it. If you kill cryptocurrency, I guarantee the only thing it will do is increase the amount of the average ransom, because they will be harder to pay and to receive. Also, ransomware is a drop in the bucket compared to other attacks like business email compromise, which often go unreported.

Re: US companies hit by 'colossal' cyber-attack

#280

Earlier quoted context omitted.

Nothing. Also nothing prevents the US government from outlawing drugs. Likely with the same effectiveness. BTW are most of these hackers transferring to fiat through U.S. exchanges? I can't imagine that's the case but maybe it is.

It’s not about stopping the hackers from accessing the exchange, it’s about preventing businesses from being able to pay ransoms.

They can still send wire transfers.
Post reply on HN