Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

471–480 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#471
post #67

Earlier quoted context omitted.

Would you mind briefly explaining the concept of "tech debt" to a layperson?

Two ways, I think they're easy to understand but I have no experience in teaching: Technical debt is like not cleaning your house to save a bit of time everyday. When you actually have to clean it, it's going to take longer than the time you saved. And until it's not clean, everything you do will be a bit worse because the house isn't clean. "Remember when you were a student and didn't do the dishes, and then when yo…

Worse than mere accumulation, it grows toxic mold.

Re: US companies hit by 'colossal' cyber-attack

#472
post #390

What are those VSA tools used for in practice? Can anyone in IT who uses them tell us. I don't mean what is sold as I mean what it is used in reality, actual operations performed.

VSA is an RMM tool, remote monitoring and management. They work as local agents to report stats, events, sw/hw inventory back to an aggregation point (on prem or in cloud), facilitate software deployment, approve and deploy updates, script execution, device configuration and compliance, and broker remote screen sharing sessions like teamviewer.

These are what they’re sold as and literally what they’re used for daily to manage and monitor thousands upon thousands of endpoints of all flavors. In a traditional on-prem Windows corporate environment these functions would have been offered by the on-prem Microsoft stack like domain services, group policy, WSUS, SCCM, SCOM, RDP, etc., and the overhead was enormous. In a diverse and dispersed environment, these toolsets have adapted accordingly - multi-platform, over-the-air, asset light. Now even internal enterprise IT shops use flavors of RMMs that MSPs would use for SMBs. MSPs can simply apply these systems to more SMBs via economies of scale, whereas an SMB could rarely afford the overhead of maintaining the tooling let alone the circus that is device management. So if you break an RMM platform used by an MSP the impact can be quite broad, and include larger enterprise IT operations. It’s easy to say “don’t use RMM tools, or switch to Macs”, but this kind of simplistic reaction belies an understanding of the environment and the need.

Re: US companies hit by 'colossal' cyber-attack

#473
post #152

I kinda feel at this stage we should go back to air gapped intranets and working from the office again. SAAS just isn't worth it, and the other things like stack overflow you can do from your phone.

SaaS is so totally worth it and is hardly the problem in this case. Though the Internet connectivity and auto-updating is getting notably untrustworthy.

Re: US companies hit by 'colossal' cyber-attack

#474

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

> But giving the keys to the castle to some mid-tier company is just a recipe for disaster It sucks, because I know my company is quite small but we take security extremely seriously (we have 9 people, 4 are security engineers, and the other 5 have varying degrees of experience in security). I think people might worry that, because of our size, we won't be as secure as a larger company. But the irony is that larger c…

This really gets at the issue. These are compliance tools mandated by auditors and accountants that are intended to provide centralized config/control of everything. Ultimately, they make companies insecure as they have tentacles into everything important. They are used against the companies (by hackers). That should not surprise anyone.

You can be compliant and buy insurance or you can be secure. Pick one.

Re: US companies hit by 'colossal' cyber-attack

#475
post #287

Earlier quoted context omitted.

Governments can stop a lot of those breaches if they applied financial and criminal (i.e. imprisonment) penalties to executives for failing to secure their systems. If every CEO and CFO's first priority is "How do I not go to prison?" and the second priority is "How do I enrich shareholders?", then security _will_ be fixed. Simple as that.

Of course, a supply-chain software company must have strong security and bear full responsibility for not having one. However, in general I wouldn't be so fast to blame victims. Strong security isn't cheap nowadays and adds to cost of doing business. To make things worse, cyber-attacks become increasingly more sophisticated, so the "security tax" will only grow and fewer organizations will be able to afford it. That'…

Security is not cheap, in real terms. Also, security is not easy to understand even by the technically competent. It’s also boring AF. Processes and tools get impacted and it’s very hard to turn the metaphoric ship that is a business operation. I know it’s contrary to the tasty trend of blaming CEOs for everything, but IME this is not a CEO problem except in a relatively narrow sense. It’s a COO problem at least as much, and a problem whose resiliency is enforced by every manager up and down the line who doesn’t want somebody pissing in their corn flakes while they’re trying to spin five bowls of corn flakes on sticks (to mix metaphors). I’m gobsmacked by how many relatively young adults lack some basic skills at thinking systemically and this retards efforts as well - even conceiving of the motivations driving initiatives, a lack of threat awareness, etc.

Re: US companies hit by 'colossal' cyber-attack

#476

This really seems like a deliberate provocation testing the "16 sectors" considered off limits, delivered to Putin from the Biden Administration. And now waiting to see what the response is going to be, whether it was an indelible line or one drawn in sand. I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware…

There is also allegedly a reciprocal agreement to allow extradition and prosecution for cyber attacks. So we'll see if that comes to pass or if it's just a little fake glad handing until you actually try to take them up on it.

That didn’t happen. Biden challenged Putin in a convo, Putin made a rejoinder about giving up criminals if the US gave up theirs. Dumbass Biden was like, “of course”, not realizing the implications of Putin’s remarks or his own ability to step on a rake, and his office promptly (like same day) walked back the comments.

Re: US companies hit by 'colossal' cyber-attack

#477

This really seems like a deliberate provocation testing the "16 sectors" considered off limits, delivered to Putin from the Biden Administration. And now waiting to see what the response is going to be, whether it was an indelible line or one drawn in sand. I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware…

Last time Biden was in office, the whole “red line” rhetoric went nowhere so I can’t say I’m surprised that Russia would test the boundaries. But I’m cynical enough that I also would t be surprised if China did the attack making it look like Russia, or even if the NSA did the attack to make it look like Russia. Or even any European country in between. Such is the my level of distrust for all of the actors involved.

Re: US companies hit by 'colossal' cyber-attack

#478
post #448

> Mr Biden said he gave Mr Putin a list of 16 critical infrastructure sectors, from energy to water, that should not be subject to hacking. This sounds like a concession of major weakness on the part of the US. I guess we already knew that Russia has outmatched US’s cyber capabilities, but I was surprised to see it acknowledged by Biden in this way. And if Russia ignores this edict, it means they’re doing so in the f…

I don’t think the US is outmatched in capabilities compared to Russia. The difference here is the tacit permission for private criminal groups to operate in Russia as long as they don’t attack Russian interests. If the US criminal justice system effectively decriminalized cyber attacks on foreign entities by the private sector, a lot more people on this forum would be rich and the scourge unleashed would make the Internet a far more interesting and hardened landscape. In other words, it’s less a product a higher class of technical capability maintained by the nation so much as the work product of a deregulated and privatized industry operating in a blue ocean.

Re: US companies hit by 'colossal' cyber-attack

#479

Earlier quoted context omitted.

I wasn't trying to say otherwise - it's a huge advantage to be this size, with regards to security. It would have taken me years at Dropbox to accomplish things that take a weekend now.

I wouldn't trust a company that implements security critical projects on the weekend...

I think you're probably misunderstanding. As an example, rolling out a policy at a company with thousands of people has to be done slowly and incrementally, with buy-in across teams, etc.

To do the same is trivial at a small company. What would take years and lots of effort becomes something you can do in spare time.

Of course, we put considerably time into security, it's not just something that one does once in a while with spare time. The point is that we can go much much faster.

Re: US companies hit by 'colossal' cyber-attack

#480

Earlier quoted context omitted.

If we, the west, let Russia take Crimea and China take Hong Kong with minimal fuss, I don't see why a few cyber attacks would get more attention.

Take over? I thought Hong Kong was given back?

It was conditionally returned to an authoritarian state with the proviso that they’d not bring their authoritarian policies to HK. Can I just say that many thought this was naive back then? And precisely because there was a lack of confidence in any nation (England and allies) to have the will to enforce the terms of that agreement kinetically. The naïveté was banking on the bright-eyed hope that China would turn a philosophical corner as economic prosperity increased, without any will power for the implied contingency plan (retaking HK). And here we are. Far from blind optimism, this was lazy hopefulness. I’m not advocating empirical crusades - simply saying that former empires (and this includes the US) cannot make red line demands unless they can be believed to dominate a kinetic engagement with a sense of real empirical ownership (resources, culture, institutions). As we see in Iraq and Afghanistan, “nation-building” is a losing exercise in attrition. Again, this should be seen only as an argument that because former empires are not capable of that commitment, they should be far more judicious in painting red lines, jealously guard their commitments to mutual defense, and not hand back occupied territory to bad actors expecting anything less than the whole consumption of those resources by that bad actor. We are about to watch Afghanistan fold back onto itself. I think it’s the right thing to do, hard as it will be to watch, but we should all understand clearly what’s about to happen and not feign surprise - it’s paying the price of a mistake made earlier. We’ve just been delaying the obvious too long. The trick to not being in this position is not putting ourselves and other countries into such positions to begin with. Similarly, England was wrong to hand back HK to the communist regime in China without the full acknowledgement that what is happening now was ever a likely outcome. To wring hands about it now is pointless.
Post reply on HN