Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

441–450 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#441

Earlier quoted context omitted.

Are you sure about that? The customers who had experience with remote work and already knew that SW products would help them in this situation was a fixed number. The number of companies who had no clue about how to do remote work, and after haphazardly had to switch to it may still have no idea that you need to use products provided by SW. Also do you really need any of that to do remote work? Of course not.

I'm sorry but I have pretty good info about SW. I can tell things are rough there. More than anything, it proved that their model is flawed. Just the number of gov agencies that are forced to stop working with them is a major blow.

You missed my point.

I agree they are not doing well, but I also do not see why they should’ve, even if the breach didn’t happen.

Re: US companies hit by 'colossal' cyber-attack

#443
post #273

Earlier quoted context omitted.

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

I have never understood this; the whole Enterprise™ security business talks about all these things where half the time I literally don't even know what they're on about. They all seem to take it very serious; great! And at the same time they miss basic stuff like, I don't know, subscribing to Apache struct release mailing list. Or not keeping employee credentials around on public servers used to file credit disputes.…

Seems like kind of a corporate/organizational culture thing. Imperfectly distributed knowledge, hierarchical decision-making in groups with misaligned incentives, the limitations of communication and the capacities of individuals... These and more make it hard to operate a large enterprise intelligently and cohesively, and oversights will happen. Corporations can certainly seem to act dumb or just learn slowly as a whole, regardless of who they're made up of. If you go bigger and look at nation-scale, the same problems are present on a greater level.

Re: US companies hit by 'colossal' cyber-attack

#444
post #427

Earlier quoted context omitted.

>These people can tell you so much about the theory of security by heart that it will make you dizzy but then won't actually understand the underlying problems. I've thought greatest failure of many professionals in this field is in the "protect the network" perspective rather than "protect the data". While many of them fess up to "we can make it difficult but not impossible" to breach the network, that is not evince…

>> Actual resting data protection would allow a "I don't care if I'm hacked," posture. That's quite interesting. Where can I read more about that ?

I think something along these lines is called “zero trust” and especially Google has been aggressively implementing it. But I could not find have any high quality articles on the concept.

https://www.csoonline.com/article/3247848/what-is-zero-trust...

Re: US companies hit by 'colossal' cyber-attack

#445

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Note that i n the case of SolarWinds, there was no demands for ransoms. It was good old state level spying, not a job to get few bitcoins.

Re: US companies hit by 'colossal' cyber-attack

#446

Earlier quoted context omitted.

Hurting who?

The companies and individuals who are attacked? Would you be okay with this happening to you or your work's computers?

It would be a great lesson of what happens when security is neglected.

Re: US companies hit by 'colossal' cyber-attack

#447

Russian state getting blamed for it in 3, 2, 1... I don't want world War 3 over stupid ransomware because of bad sys admin work and some stupid criminal groups. We should stop with this blaming. It is in Russia and other states interest to stop the ransom attacks even if they may be coming from some small group of people in their country. They have just as a hard time finding these criminals than we do finding them i…

If you think that's in the Russian government's interest you haven't been looking at what they're up to too closely. Russia isn't really that big a player globally (GDP quite a bit less than Italy's for example), but they've realised they can wield a substantial amount more power by just chaotically screwing things up for their opponents. It's the same pattern in their cyber attacks, election interference, middle eas…

>GDP quite a bit less than Italy's for example

Nominal. Closer to Germany if we are talking PPP and notably higher than Italy of course

Re: US companies hit by 'colossal' cyber-attack

#448
> Mr Biden said he gave Mr Putin a list of 16 critical infrastructure sectors, from energy to water, that should not be subject to hacking.

This sounds like a concession of major weakness on the part of the US. I guess we already knew that Russia has outmatched US’s cyber capabilities, but I was surprised to see it acknowledged by Biden in this way. And if Russia ignores this edict, it means they’re doing so in the full knowledge that it may be seen as a declaration of war? Which would lead the US to respond with its own war-like actions? High stakes.

Re: US companies hit by 'colossal' cyber-attack

#449

Oddly explosive headline, considering: > It is not clear what specific companies have been affected - a Kaseya representative contacted by the BBC declined to give details. So why "colossal"? > "This is a colossal and devastating supply chain attack," Huntress Labs' senior security researcher John Hammond said in an email to Reuters news agency. The BBC is going with "colossal" in their headline simply because the gu…

Hacker News hit by "oddly explosive" BBC headline.

The next such attack -- which will be much larger than this one -- will be called super-colossal. The next such attack.. :)

Re: US companies hit by 'colossal' cyber-attack

#450

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

Agreed. I can't imagine outsourcing monitoring/metrics/etc, despite the mild hassle of maintaining our server of one of the popular options. It requires attention every now and then, like once a year or two, but can be integrated easily with LDAP and our SSO provider.
Post reply on HN