Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

361–370 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#361

Earlier quoted context omitted.

These attacks didn't exist before crypto.

No, they typically sold stolen information on private/underground/invite forums or IRC. Instead of crypto-randomware, it would be an all out worm or booter that would crush a service who would have to acquiesce to demands. Luckily, there weren't too many good services in existence, Cloudflare didnt exist, c10k was a mind blower, webdev was AJAX, XMLRPC, and CGI. The term TLS hadn't been coined, it was still called SS…

How practical is it to transfer a million USD in gift cards to a criminal in another country on the other side of the globe? What kind of logistics would be involved?

Re: US companies hit by 'colossal' cyber-attack

#362
post #347

Earlier quoted context omitted.

The existence of credit scores has tangible benefits that we take for granted. Without such databases we would all pay much higher interest rates and many more people would be denied loans. Very wealthy people would have little trouble, but low- and middle-income people would find it far more difficult to buy a house or a car. The reason it is better to be run by a private company than the government is not that surv…

As seen from another capitalist country, namely Switzerland, I take the "higher interest" rates as a tired argumentative "canard". It's a false idea perpetrated by lobbyists. We don't have such databases. The difference here is that the bank's mortgage divisions have much lower profits, because checking somebody out is actually done by humans. It costs the credit provider more. US style mortgage broker do not exist.…

Yet another reason why I think Switzerland would be a great country to move to.

Re: US companies hit by 'colossal' cyber-attack

#363
post #326

Earlier quoted context omitted.

But that was my point exactly. Sure, you can live in Sweden without even knowing how cash looks like so it is cashless in a way. But, if the cash register is not functioning then you are done* with or without cash in your pocket. * I'd wager that if you know the prices and keep track of what you sell, you'd be fine recording the transactions after the fact.

I wouldn’t be surprised if it’s illegal to accept payment without offering a receipt with all of the correct info, which among a bunch of things include a unique incrementing receipt number.

It is more about being able to produce the receipt to the tax authorities. Even street hawkers have to have a certified machine in sweden now.

https://www4.skatteverket.se/rattsligvagledning/edition/2017...

Re: US companies hit by 'colossal' cyber-attack

#364
post #347

Earlier quoted context omitted.

The existence of credit scores has tangible benefits that we take for granted. Without such databases we would all pay much higher interest rates and many more people would be denied loans. Very wealthy people would have little trouble, but low- and middle-income people would find it far more difficult to buy a house or a car. The reason it is better to be run by a private company than the government is not that surv…

As seen from another capitalist country, namely Switzerland, I take the "higher interest" rates as a tired argumentative "canard". It's a false idea perpetrated by lobbyists. We don't have such databases. The difference here is that the bank's mortgage divisions have much lower profits, because checking somebody out is actually done by humans. It costs the credit provider more. US style mortgage broker do not exist.…

...so low- and middle-income people are not buying their own homes under that system, which is exactly what I said. What is the disagreement here?

You say that interest rates are not higher, but that is a meaningless statement if people do not generally buy their homes on credit. Low- and middle-income Americans typically buy a home using a mortgage, and credit scores are an important part of that system.

Re: US companies hit by 'colossal' cyber-attack

#365
post #306

Earlier quoted context omitted.

What does this have to do with cryptocurrencies?

Intoxication with crypto makes people too blind to see the simple things in simple ways. They go hyper-technical and philosophical and forget the fact that crypto encourages and forms the basis for payments in ALL ransomware attacks in recent times. How hard is it to see that banning crypto would help reduce the crime?

How do you "ban" crypto? Even if you think it's evil and doesn't have any useful applications that "pandora's box" has been opened and can't be closed anymore.

Re: US companies hit by 'colossal' cyber-attack

#366
post #339
post #317

Earlier quoted context omitted.

Except everyone forgot about OPM.

What is OPM ? Office of Personnel Management ?

Yes. In case you're asking what OPM is and not just the acronym intended, OPM is an agency that manages and maintains stewardship of a stupid amount of information about all employees that work for or closely with the federal government.

Background checks and investigations, healthcare related policy information, etc. e-QIP, managed by OPM specifically, collects a lot of highly sensitive information on federal employees working in the national security ecosystem was hit:

https://en.m.wikipedia.org/wiki/E-QIP#e-QIP_security_breach

Re: US companies hit by 'colossal' cyber-attack

#367
post #328

Earlier quoted context omitted.

Why isn't the local shop's systems autonomous - the should sync to the company central, sure, but they shouldn't need constant connection to lookup prices.

I think that this is the case, from the reporting it seems like it’s just their payment infrastructure that is affected. Likely they could handle cash transactions just fine. It’s just that the vast, vast majority of Swedish customers don’t use cash anymore, so it’s not worth it to keep the stores open until it’s fixed.

That sounds so wrong, they should try to use cash if they can.

Re: US companies hit by 'colossal' cyber-attack

#368

Earlier quoted context omitted.

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

>These people can tell you so much about the theory of security by heart that it will make you dizzy but then won't actually understand the underlying problems. I've thought greatest failure of many professionals in this field is in the "protect the network" perspective rather than "protect the data". While many of them fess up to "we can make it difficult but not impossible" to breach the network, that is not evince…

I always thought that when thinking security a compromised system HAS to be rebuilt. I have never seen that happen in an enterprise though. They never ever rebuild compromised systems they just try to improve perimeter protection.

Re: US companies hit by 'colossal' cyber-attack

#369
post #40

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

I know we're still pretty close to the Ubiquiti breach, but since then, they've added 2FA. Is your opinion of their products the same?

Some things, like updating firmware automatically, are ahead of their competitors.

IMHO, the worrying things about Ubiquiti at the moment are:

1. Their handling of the security breach/downplaying/whistle blowing fiasco which came to light some months ago. Check our Troy Hunts podcast from around that time.

2. Requiring a cloud account to manage your local device. Everyone seems to do that these days. It's not impossible to remove the cloud account management but it is an extra post install PITA step to work-around. And has some consequences if you do.

I'd like to see if they've learnt their lesson from at least the first point and become less opaque security-wise going forwards. Not sure their security is passing the smell test at the moment.

Re: US companies hit by 'colossal' cyber-attack

#370

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

What if Apple and Microsoft out sorces to some mid-tier company? That's what is happening in my business, the big telco/consultancy business. We're always out sourcing things and there have been several scandals related to these small to mid-tier companies that get only a small part of the contract.
Post reply on HN