Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

381–390 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#381

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

I specifically have experience with Kaseya. I kicked and screamed to get us off of it, the IT people insisted it was top notch. So when I became CFO I fired them (outside company), not just for this, but it didn’t help. It’s bad software. 24/7 full low level access is exactly what it is. We had an add on that stored admin credentials in a JSON… so looking back on that, it seems this should have happened sooner.

Additional information about the Kaseya angle:

https://doublepulsar.com/kaseya-supply-chain-attack-delivers...

Re: US companies hit by 'colossal' cyber-attack

#382

Earlier quoted context omitted.

We really need someone from REvil to do an AMA on HN for this sort of detail. How did they get their first paying "customer"? What's their churn rate? Do they appreciate strong security measures, rendering each lost "sale" somewhat bittersweet? How are they handling the transition from developer-driven startup to a more mature organization?

More importantly, how long are they on Dogecoin? (Funny post, btw. The whole thing is totally absurd.)

I know, and yet I'm only half joking because they probably face some of the same issues as any legitimate tech business. There's plenty of extra issues on top that go with any organized crime-- money laundering, worrying about law enforcement, loyalty of their members and brutal enforcement of it. I really am fascinated by what the structure of this would look like from the inside. Of course much of it depends on the degree to which it may actually be state-sponsored, or just lightly assisted or politely ignored. Now with the added prospect of a powerful country with a vendetta against them.

It's even conceivable that if they go too far and political pressure in the US builds high enough, and Russia &/or their countries of residence are also put under pressure, that they could find themselves on the wrong end of a drone strike or no-knock flash-bank assisted rapid entry to homes and business locations. All they have to do is pick the wrong target that directly leads to deaths-- hospitals the most obvious, but industrial accidents or "rapid unplanned disassembly" of something like a chemical plant...

I was shocked at the pipeline attack, followed by one on the US's food supply. These rise to the level of terrorism, and when fear & anger become dominant motivating factors the event horizon for any ability to predict what happens will become significantly shorter and less certain.

And in the middle of all of that will be a team of techies and support staff struggling to cope with day to day realities of running a thriving organization. There's an IT Crowd satire show somewhere in there that Netflix should consider.

Re: US companies hit by 'colossal' cyber-attack

#383
post #201

Earlier quoted context omitted.

Isn't Equifax a government organization? How do they have severance packages?

It's a para-state agency; while Americans don't have ID cards because they're afraid of surveillance, a private company having a complete database of everyone and veto power over mortgages is fine because it's a private company.

The state has broad enough illegal/illegitimate and legal surveillance tools that a nationwide ID card is unnecessary.

Re: US companies hit by 'colossal' cyber-attack

#384

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

You do not have to "trust" the OS at some level. Use Linux or BSD, demand open hardware. You only feel like you "have to trust" shitty closed-source OSes because the orgs behind those OSes have been able to abuse market-dominant positions to stifle competition.

Security by obscurity is laughable nonsense. We should all be demanding transparency in hardware and software from our vendors. I'd pay handsomely for it.

Re: US companies hit by 'colossal' cyber-attack

#385
post #287

So far events like this one only confirm my theory that sooner or later elected governments will start treating internet security similarly to offline security. Offline security is managed using the army, guarded borders, and internal policing. Expect similar measures in the cyberspace. The damage from cyber-attacks will only grow. When the damage they cause will start being non-trivial (and it absolutely will at som…

Governments can stop a lot of those breaches if they applied financial and criminal (i.e. imprisonment) penalties to executives for failing to secure their systems. If every CEO and CFO's first priority is "How do I not go to prison?" and the second priority is "How do I enrich shareholders?", then security _will_ be fixed. Simple as that.

Of course, a supply-chain software company must have strong security and bear full responsibility for not having one.

However, in general I wouldn't be so fast to blame victims. Strong security isn't cheap nowadays and adds to cost of doing business. To make things worse, cyber-attacks become increasingly more sophisticated, so the "security tax" will only grow and fewer organizations will be able to afford it. That's why consolidation is inevitable - it will just become more economically reasonable to share the cost of cyber-defense.

Re: US companies hit by 'colossal' cyber-attack

#387
post #374

Earlier quoted context omitted.

Yes. In case you're asking what OPM is and not just the acronym intended, OPM is an agency that manages and maintains stewardship of a stupid amount of information about all employees that work for or closely with the federal government. Background checks and investigations, healthcare related policy information, etc. e-QIP, managed by OPM specifically, collects a lot of highly sensitive information on federal employ…

Holy hell... no wonder they snuffed it out in the media. I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin. The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!" I sometime find wisdom in the approach from olden times…

> Holy hell... no wonder they snuffed it out in the media.

The OPM hack wasn’t ‘snuffed out’ by any means - it was fairly well covered for a cyber attack of it’s era. Perhaps it wasn’t covered much in your part of Eastern Europe, but it was definitely not covered up.

The fact that some people have forgotten about it is a completely different issue.

Re: US companies hit by 'colossal' cyber-attack

#388
post #374

Earlier quoted context omitted.

Yes. In case you're asking what OPM is and not just the acronym intended, OPM is an agency that manages and maintains stewardship of a stupid amount of information about all employees that work for or closely with the federal government. Background checks and investigations, healthcare related policy information, etc. e-QIP, managed by OPM specifically, collects a lot of highly sensitive information on federal employ…

Holy hell... no wonder they snuffed it out in the media. I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin. The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!" I sometime find wisdom in the approach from olden times…

[deleted]

Re: US companies hit by 'colossal' cyber-attack

#389
post #95

Earlier quoted context omitted.

This isn't really true. Stock price is not an indicator of a company's "bottom line". As someone who helps respond to major breaches at big companies, these types of breaches often result in enormous expenditures on company-wide efforts to close security gaps or revamp processes. Either a regulatory agency, or more often the company's board of directors, will make a mandate to the C-suite that something must be done.…

Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line. Sure, expenses rise a bit for a short period of time, but these are not catastrophic by any means. I mean, I'm looking at Solarwinds last earnings statement and comparing quarters from last year to now, they are up about 3.5% in re…

> they are up about 3.5% in revenue

Revenue != bottom line. Bottom line is profit, ie revenue minus expenses.

Post reply on HN