Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

321–330 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#321

Earlier quoted context omitted.

Can you explain more about the ‘root ash’ issue please?

By using some of these tools they are under the false assumption that things that are otherwise considered security threats are somehow okay because for example the tool rotates passwords for you. It gives a false sense of security and allows you to do things that would otherwise be considered security threats. It's as if someone sells you a laser that shoots intruders and tells you, you can leave the front door open…

I see so if people have cyberark they might feel like it’s safe to enable root logins over ssh? That does sound like the sort of thing that would happen.

Re: US companies hit by 'colossal' cyber-attack

#322
post #255

Earlier quoted context omitted.

IMO, a big issue is conflating monitoring with management. Management is always going to have access, so maybe you should not enable remote management access of everything to a centralized system? Make it lean and secure, possibly segmented, dual-factor, use HSM etc. Monitoring - there is no good reason why it should have access to anything. Make it ingest only (use firewalls and reasonable protocols), and you've cut…

There are trade offs there as well. Now you've decreased the attack surface, but still every foreign agent is a legalized rce. Observe that the case of Kaseya is not direct hacking of the agent, but a compromised update where firewall rules won't help. As I said, the next level of the argument is that this rce is dangerous and what it lacks is a privilege escalation. At the same time, you don't have a way to solve a…

If the software used a one-way protocol, then unless you updated the closed-source agents, which are the parts I have the biggest issue with, there wouldn't be RCE.

As for remote management. I'm saying you should wisely choose what needs to be remotely managed, what doesn't, what are the foundations for your security and then balance it with reasonable methods to secure access. Which would probably not be "Kaseya VSA Remote Monitoring and Management" for all your systems and devices.

Yes, make sure you don't need on-site personnel to restart your web server, but maybe also don't expose management of your switch that you never reconfigure to your monitoring SW, and maybe use separate HSMs¹ or at least HSMs instead of the enterprise management system for the most important parts.

¹ e.g. FIDO2 ed25519 for ssh

Re: US companies hit by 'colossal' cyber-attack

#323
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

> Only now that insurance companies have paid out the nose with ransomware incidents have they started to wise up.

Exactly right, and eventually they will GET A CLUE, and require serious security audits to get a sane price on incident insurance. Otherwise they will make you pay gobs and gobs of money, and it will just be cheaper to be sane about your security posture.

Otherwise there is zero incentive for the insurance companies to keep paying out the nose on policies they aren't making money from.

This has happened to police stations, as they get mismanaged by idiot police chiefs, the insurance providers say.. uh we aren't going to insure you anymore unless you fix your sh*t. As but one example: https://www.theatlantic.com/politics/archive/2017/06/insuran...

I see this happening to cyper security policies also, they(insurance companies) will wise up or go broke.

Re: US companies hit by 'colossal' cyber-attack

#324
post #298

Earlier quoted context omitted.

It's almost as if making shareholder returns and CEO pay the only indicator of company success creates terrible consequences.

Juice the returns at all costs for a few quarters and then walk away with riches from total ruins, you say?

This is the way.

Re: US companies hit by 'colossal' cyber-attack

#325

Russian state getting blamed for it in 3, 2, 1... I don't want world War 3 over stupid ransomware because of bad sys admin work and some stupid criminal groups. We should stop with this blaming. It is in Russia and other states interest to stop the ransom attacks even if they may be coming from some small group of people in their country. They have just as a hard time finding these criminals than we do finding them i…

You have obviously failed to notice that we are already in an increasingly hot war with the Russian govt (which is in reality a transnational criminal syndicate masquerading as a govt).

Any attempt to avoid conflict under the guise of avoiding current hot war actions is merely understood by these actors as weaknesses and permission to take more territories, libreties, and/or criminal actions. This will eventually lead to conflict, and the longer the delay, the larger and mor damaging the eventual conflict.

If you want to avoid large war(or even "WW3"), the solution is to take serious diplomatic, financial, and kinetic (all 3) actions immediately, si that the perceived costs immediately escalate beyond any possible benefits to Vlad and his ilk.

If you want more information, read people who have a deep understanding of the situation and have skin in the game, such as Garry Kasparov, former world chess champion & Russian presidential candidate currently in exile, and Bill Browder, former Russian investment fund founder & progenitor of the Magnitski sanctions being effectively deployed around the world. Both have been there, done that, and buried their friends for their efforts.

Peace is a wonderful goal, but not at the expense of allowing autocrats & criminals free reign - they will stop at nothing and eventually take everything.

Re: US companies hit by 'colossal' cyber-attack

#326
post #292

Earlier quoted context omitted.

You can pay with cash at Coop. Most if not all cash registers allow cash payments. Most customers don't pay with cash.

Yes but how does the cashier know what the price is? How does the cashier open the safety box to reach the money? Or open the cash registry? I don't even think it is legal to accept money without a working cash registry for tax registration reasons.

But that was my point exactly. Sure, you can live in Sweden without even knowing how cash looks like so it is cashless in a way. But, if the cash register is not functioning then you are done* with or without cash in your pocket.

* I'd wager that if you know the prices and keep track of what you sell, you'd be fine recording the transactions after the fact.

Re: US companies hit by 'colossal' cyber-attack

#327

These kinds of games, and the all-nighter / weeks long nightmares they cause, make me want to leave this industry. We set up software on a lot of machines and then we answer a million ridiculous user questions until we finally resort to installing remote access so we don't have to stay up all night telling people what to type into a command line. Then the remote access gets hacked en masse. I'm pretty much at the poi…

> I'm pretty much at the point of thinking people need to learn how to write on paper and whiteboards again.

Health IT here: won't happen.

You need your CT NOW. The patient is about to be opened. There is no time to wait for the printer and it's Sunday night. The radiologist is at home examining the data while the scanner runs.

And man...security is so bad and it's so hard to convince management to invest into proper security. Also everything that breaks or even slightly slows down workflows is just unacceptable.

I'm sweating hard with every wide scale attack out there expecting the next big thing to hit us. The targeted ones I just don't even want to think about.

Re: US companies hit by 'colossal' cyber-attack

#328
post #252

Earlier quoted context omitted.

I dont think this is necessarily due to 'cashless' as much as general computerization. Stuff like prices, article numbers and inventory are likely all digitized nowadays, so even if people could pay with cash I imagine they'd still be keeping closed.

Why isn't the local shop's systems autonomous - the should sync to the company central, sure, but they shouldn't need constant connection to lookup prices.

I think that this is the case, from the reporting it seems like it’s just their payment infrastructure that is affected. Likely they could handle cash transactions just fine. It’s just that the vast, vast majority of Swedish customers don’t use cash anymore, so it’s not worth it to keep the stores open until it’s fixed.

Re: US companies hit by 'colossal' cyber-attack

#329
post #326

Earlier quoted context omitted.

Yes but how does the cashier know what the price is? How does the cashier open the safety box to reach the money? Or open the cash registry? I don't even think it is legal to accept money without a working cash registry for tax registration reasons.

But that was my point exactly. Sure, you can live in Sweden without even knowing how cash looks like so it is cashless in a way. But, if the cash register is not functioning then you are done* with or without cash in your pocket. * I'd wager that if you know the prices and keep track of what you sell, you'd be fine recording the transactions after the fact.

I wouldn’t be surprised if it’s illegal to accept payment without offering a receipt with all of the correct info, which among a bunch of things include a unique incrementing receipt number.

Re: US companies hit by 'colossal' cyber-attack

#330
post #292

Earlier quoted context omitted.

You can pay with cash at Coop. Most if not all cash registers allow cash payments. Most customers don't pay with cash.

Yes but how does the cashier know what the price is? How does the cashier open the safety box to reach the money? Or open the cash registry? I don't even think it is legal to accept money without a working cash registry for tax registration reasons.

> Yes but how does the cashier know what the price is?

My understanding was that it was just payment processing that was affected, not the point of sale systems. The scanners and things probably work fine, and I think they could accept cash payments without issue. It’s just not worth it when almost no customer pays with cash.

Post reply on HN