Live data from Hacker News

Winnti: Hackers attacking the heart of German industry

br24.de

1–10 of 154 posts

Re: Winnti: Hackers attacking the heart of German industry

#2
This group of german companies founded their own security group [German Cyber Security Organization (DCSO)]. That speaks a lot about their trust in their public services.

The only time I've been involved in a hacking attempt (it was ransomware) the company I work for contacted the CCN-CERT. I wonder if US companies contact NSA/Other gov agencies or deal with it themselves with security companies.

Also, while I understand the care and concern they put into securing their networks, many german companies basically gift their tech to china, like Deutsche Bahn, or being bought and transfered there, like it happend with Kuka. So be it by hacking into your network or "partnering", they'll copy your tech and kick you out of their market sooner or later.

Re: Winnti: Hackers attacking the heart of German industry

#5
post #2

This group of german companies founded their own security group [German Cyber Security Organization (DCSO)]. That speaks a lot about their trust in their public services. The only time I've been involved in a hacking attempt (it was ransomware) the company I work for contacted the CCN-CERT. I wonder if US companies contact NSA/Other gov agencies or deal with it themselves with security companies. Also, while I unders…

Probably because when it comes to anything cyber-related, the German government, like most big companies there, is a dinosaur, greatly inferior to it's British and Swiss counterparts.

Re: Winnti: Hackers attacking the heart of German industry

#7
post #4

What an obnoxious presentation. And I'm paying for this garbage.

Not really sure what is so obnoxious about this. The whole article is made up like the NYTimes interactive articles are. Quite a high design standard to compare to and they're doing pretty well. No idea what you are talking about.

Re: Winnti: Hackers attacking the heart of German industry

#8
post #4

What an obnoxious presentation. And I'm paying for this garbage.

What are your specific criticisms? A blanket dismissal is not very helpful and additionally sort of off-topic.

For what it’s worth I found the presentation to be excellent. Extremely well readable, clear focus on text presentation and typography, tasteful illustrations that stay back and give the text the center stage but are still for the most part helpful, extremely well done and tasteful animations. (I read this on my phone so I don’t know how this looks on a wider viewport.)

Re: Winnti: Hackers attacking the heart of German industry

#9
post #3

Is this a good way of tracking an APT? Just from bytecode? Isn't that easy to fake? What if they were tracking Russian hackers instead?

If I'm understanding the article correctly, the hackers are using a easily reversed cypher for storing configuration data for their malware, which was reversed by assuming the presence of the string "C:\Windows\System". In the following decrypted data the name of the respective company targeted was found.

Yes I suppose it would be easily faked if the faker had performed a similar analysis on the malware...

Re: Winnti: Hackers attacking the heart of German industry

#10
As of today we still use shared network drives for everything in major German company. We don’t use slack/irc/Skype/zoom/whatever. Phone calls and conferences(!) from the middle of open office is normal. Asana/Trello/Jira are not known at all. GitHub is paid for, but never used. I am single weirdo in multi department project using github ticket system. The code with prefix is copied for colleagues to project’s shared folder. PostIt tickets on the table works good enough for others. Talking about bugs is impossible since nobody knows what’s fixed and what’s not, the bugs have date in the best case. Everything else is done in Excel sheets using in house written scripts. They usually end in a mess since some people use German regional settings and other English ones. That’s state-of-art situation in very rich and big company today. I don’t see any possible changes in future. Old boy club fights all the time against proposed improvements. You can forgot topics like information security, phishing, being silent about work topics outside the office. Hackers are known from the American movies only.

On the other hand I also worked in opposite unhealthy paranoid environment. I was hired to design Ethernet camera, but Wireshark usage in their office was prohibited. Packet analysis was seen as the worst thing in the company. I quit after few months trying to explain, that I need to analyze the packets during design phase. I think, it’s very normal, that other countries abuse illiteracy of German industry.

Post reply on HN