Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

281–290 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#281
post #255

Earlier quoted context omitted.

I'd agree partially with you. However, once a remote agent is compromised, it will be chained with some privilege escalation vulnerability and this same argument will be repeated with the twist that now every foreign executable with remote connection is an attack surface. Having hundreds of people in each location whose only task is to do a boring monitoring an very occasional management tasks is a waste of your reso…

IMO, a big issue is conflating monitoring with management. Management is always going to have access, so maybe you should not enable remote management access of everything to a centralized system? Make it lean and secure, possibly segmented, dual-factor, use HSM etc. Monitoring - there is no good reason why it should have access to anything. Make it ingest only (use firewalls and reasonable protocols), and you've cut…

There are trade offs there as well. Now you've decreased the attack surface, but still every foreign agent is a legalized rce. Observe that the case of Kaseya is not direct hacking of the agent, but a compromised update where firewall rules won't help. As I said, the next level of the argument is that this rce is dangerous and what it lacks is a privilege escalation.

At the same time, you don't have a way to solve a problem that your monitor has alerted you for. Every solution proposed includes either a person at the location who does the job manually or a way to connect to the network from the outside which is vulnerable to similar attacks as before with added costs and possibilities to mismanage keys and passwords.

Security vs convenience is a well-known dilemma that people very often love to solve in the most absolutist way.

Re: US companies hit by 'colossal' cyber-attack

#282

Earlier quoted context omitted.

Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.

Sounds so spooky, do say more! Do you mean Jason Bourne / John Wick shows up at the hackers’ nest?

Well, if the attacker manages to kill a few thousand people, there's precedent for the USA going to war over it. It would depend on the host nation of course, if it was e.g. China, Russia or some state in their sphere of influence, it'd be different than if the hackers were holed out in, say, Afghanistan.

Re: US companies hit by 'colossal' cyber-attack

#283

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

Yes, and there is a reason why big IT providers like Accenture are preferred enterprise vendors. They have the financial power to mitigate such risks. There are usually vendor risk checks which include potential damage costs.

Re: US companies hit by 'colossal' cyber-attack

#284
So far events like this one only confirm my theory that sooner or later elected governments will start treating internet security similarly to offline security. Offline security is managed using the army, guarded borders, and internal policing. Expect similar measures in the cyberspace. The damage from cyber-attacks will only grow. When the damage they cause will start being non-trivial (and it absolutely will at some point), governments will start creating safe internet zones with heavy policing.

Re: US companies hit by 'colossal' cyber-attack

#285
I wish a country would pass the following law:

1. Any company that makes software with low-level access to systems (i.e. admin privileges on Windows, root privileges on UNIX systems) is criminally responsible for any security breaches of its software, unless it can prove that it took all reasonable steps to keep their software safe.

2. The CEO and CFO will receive a mandatory 30 day jail sentence on the first instance of a breach with consequential damage.

3. The jail sentence will be tripled if the company downplayed or omitted to report any security breaches.

4. The minimum sentence increases by 30 days for each subsequent breach linked to an executive, and resets after 10 years of no breaches.

Re: US companies hit by 'colossal' cyber-attack

#286

Russian state getting blamed for it in 3, 2, 1... I don't want world War 3 over stupid ransomware because of bad sys admin work and some stupid criminal groups. We should stop with this blaming. It is in Russia and other states interest to stop the ransom attacks even if they may be coming from some small group of people in their country. They have just as a hard time finding these criminals than we do finding them i…

If you think that's in the Russian government's interest you haven't been looking at what they're up to too closely.

Russia isn't really that big a player globally (GDP quite a bit less than Italy's for example), but they've realised they can wield a substantial amount more power by just chaotically screwing things up for their opponents.

It's the same pattern in their cyber attacks, election interference, middle east policy, online disinformation spreading, etc etc. None of it's directly for their own benefit, it's purely to harm opponents.

Re: US companies hit by 'colossal' cyber-attack

#287

So far events like this one only confirm my theory that sooner or later elected governments will start treating internet security similarly to offline security. Offline security is managed using the army, guarded borders, and internal policing. Expect similar measures in the cyberspace. The damage from cyber-attacks will only grow. When the damage they cause will start being non-trivial (and it absolutely will at som…

Governments can stop a lot of those breaches if they applied financial and criminal (i.e. imprisonment) penalties to executives for failing to secure their systems.

If every CEO and CFO's first priority is "How do I not go to prison?" and the second priority is "How do I enrich shareholders?", then security _will_ be fixed. Simple as that.

Re: US companies hit by 'colossal' cyber-attack

#288
post #285

I wish a country would pass the following law: 1. Any company that makes software with low-level access to systems (i.e. admin privileges on Windows, root privileges on UNIX systems) is criminally responsible for any security breaches of its software, unless it can prove that it took all reasonable steps to keep their software safe. 2. The CEO and CFO will receive a mandatory 30 day jail sentence on the first instanc…

I’m not in favor of this. For this to be reasonable, coming from someone who writes exploits for work and fun, you need to define all. Otherwise you’ll be unreasonably putting people in already overcrowded and underfunded jails. Instead of jail, consider a more reasonable and realistic punishment.

Re: US companies hit by 'colossal' cyber-attack

#289

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

> But giving the keys to the castle to some mid-tier company is just a recipe for disaster It sucks, because I know my company is quite small but we take security extremely seriously (we have 9 people, 4 are security engineers, and the other 5 have varying degrees of experience in security). I think people might worry that, because of our size, we won't be as secure as a larger company. But the irony is that larger c…

> We plan to give talks and blog about how companies at our stage can do things that would make companies 100x our size jealous

Sounds interesting and rather extraordinary, would be great to read more on your thoughts on that. Do you refer to the Grapl blog?

Re: US companies hit by 'colossal' cyber-attack

#290

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

> I'd be willing to trust security to Microsoft

Well then I guess we will have a lot threats from hackers for days to come.

Post reply on HN