Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

391–400 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#391

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Give it time, these are start-ups bootstrapping themselves. They don't have the support infrastructure in place yet to scale to beyond a few hundred companies. As it is, there are going to be a lot of over-worked people at REvil doing crunch time, missing family dinners and their kids' recitals and soccer games managing the logistics of this hack. No worries though, the ransom from this round should serve nicely as a…

Unsure why everyone is acting like this is a new phenomena. These organizations have been getting multi-million payments for the better part of a decade, it is just only being covered by the media now.

Why couldn't they have bootstrapped years ago? I suspect the real reason is they actually want to avoid extensive media coverage.

Re: US companies hit by 'colossal' cyber-attack

#392
post #192

Earlier quoted context omitted.

As I understand it there is often a lot of discourse that takes place between the hacker and the hacked - agreeing prices, haggling, proof of files etc. Yes much can be automated but there is usually a human element to these deals and that costs the hackers money. They also want to be careful to limit their hacks to companies their handlers are happy for them to hack. Go too wide and you risk hitting a company direct…

You'd think a GPT3 / GAN could be created to handle much of that. It's a percentages game anyway.

Why would you want GPT to handle multi million dollar negotiations?

Sorta playing into stereotypes about engineers here.

Re: US companies hit by 'colossal' cyber-attack

#393

Earlier quoted context omitted.

Maybe you’re a state actor and a ransom demand, at least an overt one, is not your objective.

My mind went there as well. Say I'm an affluent oligarch shorting major companies. I'd paying the ransom group to massively attack the company or various companies. Then cash out during the chaos.

Yes, except for the fact that we don't hear about most of these attacks because both the attacker and attacked keep them quiet.

That doesn't jive with your market manipulation hypothesis.

Re: US companies hit by 'colossal' cyber-attack

#394
post #380

Earlier quoted context omitted.

ISC² has done so much damage to the industry via enabling the fallacy of appeal to false authority it is mind-blowing. The cissp is such a terrible proof of whether someone knows anything, everyone knows it, but for some reason people keep falling for it.

I view it as a shared level of baseline knowledge that helps with conversation. If I see someone has it, it at least tells me they understand the words I’m using and have a basic knowledge of the concepts we are discussing (or should, at least). It also tells me they are good at taking tests. It doesn’t tell me whether they understand how it all works together, or if they understand the organization’s environment, or…

I wish that were true (genuinely, a shared vocab would be super useful). I've heard so many nonsensical things from CISSPs, I should really start a parody Twitter account. Did you know, for instance, that SSL is an important control for preventing SQL injection? How about that salting is not effective against rainbow tables because of the birthday paradox (yes that's actually what they said).

It's just a cram-and-forget vocab test, it doesn't mean anything other than that they could afford the training and the test.

Re: US companies hit by 'colossal' cyber-attack

#395
post #218

Earlier quoted context omitted.

> like fines and people going to jail for negligence Being bad at your job is not negligence, nor is underestimating the threat. It’d be nice to see consequences but I really don’t want to have the government locking people up for being well-paid fuck-ups. Don’t some of these companies have… shareholders?

If you screw it up with a building or a bridge, you might go to jail, and we as a society are fine with that. Why not in this case as well?

It is 100% possible to be really good at InfoSec, do everything right, and still be breached.

I think there’s a (very simplistic) view of IS, where it’s a black and white process of just engineering everything ’correctly’. It’s not like that in the real world…

Re: US companies hit by 'colossal' cyber-attack

#396

Earlier quoted context omitted.

FWIW though (and I don't have easily available "sources") there was this immediate retaliation where Biden was like "we will completely prosecute these offenders" and within days DarkSide PR department said "Hey sorry we didn't mean to disrupt core services, we just want money" (sic) So it's a spectrum

That's not even close to what happened. The administration left it alone for days saying they'll let private business sort it out. (Default investigation notwithstanding.) When a bunch of news media started reporting the group was Russian and then insinuate it was a state sponsored attack, DarkSide said something along the lines of, "We didn't realize this would start geopolitical conflict. We will be careful to vet…

They also accepted a ransom substantially below their typical going rate. The Darkside people were probably shitting their pants, this is not what they intended at all.

Re: US companies hit by 'colossal' cyber-attack

#397

Earlier quoted context omitted.

You'd think a GPT3 / GAN could be created to handle much of that. It's a percentages game anyway.

Why would you want GPT to handle multi million dollar negotiations? Sorta playing into stereotypes about engineers here.

Scale.

Perhaps not the largest groups, but the smaller ones, posssibly.

Re: US companies hit by 'colossal' cyber-attack

#399
post #322

Earlier quoted context omitted.

There are trade offs there as well. Now you've decreased the attack surface, but still every foreign agent is a legalized rce. Observe that the case of Kaseya is not direct hacking of the agent, but a compromised update where firewall rules won't help. As I said, the next level of the argument is that this rce is dangerous and what it lacks is a privilege escalation. At the same time, you don't have a way to solve a…

If the software used a one-way protocol, then unless you updated the closed-source agents, which are the parts I have the biggest issue with, there wouldn't be RCE. As for remote management. I'm saying you should wisely choose what needs to be remotely managed, what doesn't, what are the foundations for your security and then balance it with reasonable methods to secure access. Which would probably not be "Kaseya VSA…

So, now you have one hardware key that you have to manage either for all networks and therefore is both a single point of failure and constraint on availability, or you need to manage multiple keys with the ensuing chaos. Kaseya was hacked through a patch so the type of protocol does not matter and you are trading convenience for management overhead that you have to deal with because all of your clients and likely many of your employees are not in your HQ.

I have the bad feeling that this achieves security through unavailability.

Re: US companies hit by 'colossal' cyber-attack

#400
post #287

So far events like this one only confirm my theory that sooner or later elected governments will start treating internet security similarly to offline security. Offline security is managed using the army, guarded borders, and internal policing. Expect similar measures in the cyberspace. The damage from cyber-attacks will only grow. When the damage they cause will start being non-trivial (and it absolutely will at som…

Governments can stop a lot of those breaches if they applied financial and criminal (i.e. imprisonment) penalties to executives for failing to secure their systems. If every CEO and CFO's first priority is "How do I not go to prison?" and the second priority is "How do I enrich shareholders?", then security _will_ be fixed. Simple as that.

> Governments can stop a lot of those breaches if they applied financial and criminal (i.e. imprisonment) penalties to executives for failing to secure their systems

And how do you codify that? It’s possible to be breached when following best practices and doing everything right..

Post reply on HN