I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.
Toothpaste's out of the tube. Banning the exchanges won't stop the ransomware.
US companies hit by 'colossal' cyber-attack
311–320 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#312These kinds of games, and the all-nighter / weeks long nightmares they cause, make me want to leave this industry. We set up software on a lot of machines and then we answer a million ridiculous user questions until we finally resort to installing remote access so we don't have to stay up all night telling people what to type into a command line. Then the remote access gets hacked en masse. I'm pretty much at the poi…
Windows, right?
Re: US companies hit by 'colossal' cyber-attack
#313Re: US companies hit by 'colossal' cyber-attack
#314Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…
Re: US companies hit by 'colossal' cyber-attack
#315Earlier quoted context omitted.
It's a para-state agency; while Americans don't have ID cards because they're afraid of surveillance, a private company having a complete database of everyone and veto power over mortgages is fine because it's a private company.
There's three companies doing it, so they possess the holy blessings of the all-knowing market \s
Re: US companies hit by 'colossal' cyber-attack
#316I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
At some point you cross the threshold of "this is too much, drone them". Or send an assassin. Yes, even the United States does this occasionally. I suspect the attackers know this. Or else they aren't in it for the money. One or the other.
Re: US companies hit by 'colossal' cyber-attack
#317Earlier quoted context omitted.
“After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.” It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after th…
It's worse than PII leaks and CEOs stepping down. Lax security has become scary. The U.S. Nuclear Weapons Agency was breached shortly after SolarWinds. Let's also not forget about OPM.
Re: US companies hit by 'colossal' cyber-attack
#318Really good thread here: https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransom... When these things happen, I feel like there's a predictable response. A few smaller vendors (above, Huntress Labs) provide a great running commentary. Then two weeks later, the dust has settled, everyone's patched, and I'll start receiving sales calls from Enterprise Vendor X wanting to talk about how they were all over it.
https://csirt.divd.nl/2021/07/03/Kaseya-Case-Update/
> we were already running a broad investigation into backup and system administration tooling and their vulnerabilities. One of the products we have been investigating is Kaseya VSA. We discovered severe vulnerabilities in Kaseya VSA and reported them to Kaseya, with whom we have been in regular contact since then. Additionally, we have, in confidence, also reported these vulnerabilities to our trusted partners.
Re: US companies hit by 'colossal' cyber-attack
#319Earlier quoted context omitted.
What does this have to do with cryptocurrencies?
Intoxication with crypto makes people too blind to see the simple things in simple ways. They go hyper-technical and philosophical and forget the fact that crypto encourages and forms the basis for payments in ALL ransomware attacks in recent times. How hard is it to see that banning crypto would help reduce the crime?
Re: US companies hit by 'colossal' cyber-attack
#320Earlier quoted context omitted.
I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)
Intoxication with crypto makes people too blind to see the simple things in simple ways. They go hyper-technical and philosophical and forget the fact that crypto encourages and forms the basis for payments in ALL ransomware attacks in recent times. How hard is it to see that banning crypto would help reduce the crime?