Live data from Hacker News

Heartbleed hack case sees first arrest in Canada

bbc.co.uk

1–10 of 37 posts

Re: Heartbleed hack case sees first arrest in Canada

#6
Direct link to the CRA response http://www.cra-arc.gc.ca/gncy/sttmnt2-eng.html

"Regrettably, the CRA has been notified by the Government of Canada's lead security agencies of a malicious breach of taxpayer data that occurred over a six-hour period."

That seems to be implying that another government agency (RCMP? CSEC?) monitors at least the CRA network and does some kind of deep packet inspection and/or packet logging. So are they logging every packet that gets sent to the CRA network? Or did they know about it beforehand and could detect it in real time with an IDS?

Re: Heartbleed hack case sees first arrest in Canada

#7
post #2

[deleted]

Did you read the article? He was arrested for stealing 900 social insurance numbers from CRA (Canada Revenue Agency, Canada's IRS).

While he obviously behaved rather irresponsibly, talking openly about a hack he did, the word steal is probably a bit strong.

Odds are the insurance numbers are just some of the things that passed through while he performed the hack, or the first thing he saw when he got in. Not something he intentionally took for his own gain.

Re: Heartbleed hack case sees first arrest in Canada

#9
post #6

Direct link to the CRA response http://www.cra-arc.gc.ca/gncy/sttmnt2-eng.html "Regrettably, the CRA has been notified by the Government of Canada's lead security agencies of a malicious breach of taxpayer data that occurred over a six-hour period." That seems to be implying that another government agency (RCMP? CSEC?) monitors at least the CRA network and does some kind of deep packet inspection and/or packet loggin…

Also mentioned in that link is Shared Services Canada, which appears to be a division that's tasked with bringing the various departments' IT infrastructures under a single umbrella. From their website (http://www.ssc-spc.gc.ca/index-eng.html):

"Shared Services Canada was created on August 4, 2011 to fundamentally transform how the Government manages its information technology (IT) infrastructure. Its mandate for the provision of enterprise-wide IT-infrastructure services represents better value for money and a more reliable IT infrastructure to support modern government operations."

Re: Heartbleed hack case sees first arrest in Canada

#10
post #6

Direct link to the CRA response http://www.cra-arc.gc.ca/gncy/sttmnt2-eng.html "Regrettably, the CRA has been notified by the Government of Canada's lead security agencies of a malicious breach of taxpayer data that occurred over a six-hour period." That seems to be implying that another government agency (RCMP? CSEC?) monitors at least the CRA network and does some kind of deep packet inspection and/or packet loggin…

Agreed, it's quite impressive they were able to detect this attack and find its source so quickly after a brand new vulnerability was exposed.

If a central agency is managing security for various important government systems, they may have full packet capture logging for up to the past 48 hours or longer.

An analyst may have downloaded the entire packet capture and used a tool like Wireshark to drill down into all heartbeat requests, and then use filters to find suspicious and malformed requests. One example of how they could do this is with the advice given here: http://security.stackexchange.com/a/55533

Post reply on HN