US companies hit by 'colossal' cyber-attack
301–310 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#302I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
Re: US companies hit by 'colossal' cyber-attack
#303Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…
A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…
I've thought greatest failure of many professionals in this field is in the "protect the network" perspective rather than "protect the data". While many of them fess up to "we can make it difficult but not impossible" to breach the network, that is not evinced by the protections instituted.
If companies actually understood that they WILL be hacked, the focus would turn to protecting the data. Actual resting data protection would allow a "I don't care if I'm hacked," posture. Either behind encryption, VM's, segregation, or architectures, preferably all, if data is actually protected, then a hack can be weathered. It's still a pain if the computer-touchers have to rebuild and reload, but that's what you pay them for. If the data is protected, a hack is just a painful exercise rather than a newsworthy event.
I do understand that segregating (through protection and architecture) data is difficult, but I do not understand why it is not the focus.
Re: US companies hit by 'colossal' cyber-attack
#304Re: US companies hit by 'colossal' cyber-attack
#305Earlier quoted context omitted.
A cashless society is scary. Cash should always be an option and the inventory system should be disconnected from the internet.
You can pay with cash at Coop. Most if not all cash registers allow cash payments. Most customers don't pay with cash.
How does the cashier open the safety box to reach the money?
Or open the cash registry?
I don't even think it is legal to accept money without a working cash registry for tax registration reasons.
Re: US companies hit by 'colossal' cyber-attack
#306I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.
What does this have to do with cryptocurrencies?
Re: US companies hit by 'colossal' cyber-attack
#307I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.
I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)
Re: US companies hit by 'colossal' cyber-attack
#308Re: US companies hit by 'colossal' cyber-attack
#309I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.
Ransomware is not an innovation that came as a result of cryptocurrency, it was just accelerated by it. If you kill cryptocurrency, I guarantee the only thing it will do is increase the amount of the average ransom, because they will be harder to pay and to receive. Also, ransomware is a drop in the bucket compared to other attacks like business email compromise, which often go unreported.
Re: US companies hit by 'colossal' cyber-attack
#310Russian state getting blamed for it in 3, 2, 1... I don't want world War 3 over stupid ransomware because of bad sys admin work and some stupid criminal groups. We should stop with this blaming. It is in Russia and other states interest to stop the ransom attacks even if they may be coming from some small group of people in their country. They have just as a hard time finding these criminals than we do finding them i…
So yes Russia might be blamed as they consciously choose to let these guys do their thing. China and NK do the same, as do US, UK and Israel with similar stuff on the other side, done by NSA, CiA, etc