Live data from Hacker News

State of Cybersecurity Industry Exposure at Dark Web

immuniweb.com

11–20 of 28 posts

Re: State of Cybersecurity Industry Exposure at Dark Web

#13
post #7

While the evidence is light. Is anyone surprised if this is true? My experience is that most cybersecurity firms are only slightly better than other enterprises. They often have lofty standards that they themselves don't follow. They also have professional service arms that are similar to the rest of the industry. Handful of senior people and an army of junior engineers that bias towards velocity over quality (i.e. t…

I know an attorney who was quite capable legally and with tech and spent his career in both. He ended up at a legal organization that also dealt with security.

The cybersecurity industry is absolutely full of crappy security companies worth jack squat. The legal industry is full of Luddites.

Being capable in both areas = some serious demand / profit.

Re: State of Cybersecurity Industry Exposure at Dark Web

#14
post #10
post #9

Earlier quoted context omitted.

It looks like it’s based on looking for the companies’ domains in password and data dumps, in which case 97% is utterly unsurprising and I bet the 3% are just too new to have had any users in a major breach.

How exactly does that work though? I'm not connived that every name in a data dump indicates a breach at a given company. My thinking: If someone gets a hold of a huge list of usersnaems and passwords from bobcompany.com, and then spams numerous sites with those logins to see if they work elsewhere ... and finds that a few work on joecompany.com then puts out that data.... joecompany.com might have their name listed…

Yeah, this is meaningless marketing scare tactics.

Re: State of Cybersecurity Industry Exposure at Dark Web

#15
post #10
post #9

Earlier quoted context omitted.

It looks like it’s based on looking for the companies’ domains in password and data dumps, in which case 97% is utterly unsurprising and I bet the 3% are just too new to have had any users in a major breach.

How exactly does that work though? I'm not connived that every name in a data dump indicates a breach at a given company. My thinking: If someone gets a hold of a huge list of usersnaems and passwords from bobcompany.com, and then spams numerous sites with those logins to see if they work elsewhere ... and finds that a few work on joecompany.com then puts out that data.... joecompany.com might have their name listed…

I agree.

Every work email address I've ever had has been a part of at least one breach according to haveibeenpwned. None of them are specific to the companies I've worked for. If they count things like the Exactis breach, they'll likely pick up every company that existed prior to that breach.

Re: State of Cybersecurity Industry Exposure at Dark Web

#16

I have asked this in several forums but didn't get any satisfactory answer. How does one get started in dark web monitoring for intelligence, like finding these leaked databases or confirming/denying the reports of data leak in "the dark web".

Are you asking from a career or technical perspective?

This report isn't particularly technically complex, a majority of this sort of leaked data is widely available on clearweb forums. The minority requires building relationships and/or paying and/or developing a reputation that gets you access to more exclusive forums or circles. You then have to regularly crawl those forums, and avoid identification of your crawlers (as the more exclusive forums/site watch out for that sort of activity pattern). Then you just index the data and can perform searches or analysis.

https://scylla.sh/ is a free example covering just breach data.

From a career perspective, this is a subset of threat intelligence. The more interesting companies in this space often are leveraging military-style HumInt to gain access to these marketplaces and data, and often have leadership from that sort of military or government background. Most folks I'd assume are just standard engineers however, as a majority of the work is probably not specific to "dark web monitoring for intelligence."

Re: State of Cybersecurity Industry Exposure at Dark Web

#17
post #10
post #9

Earlier quoted context omitted.

It looks like it’s based on looking for the companies’ domains in password and data dumps, in which case 97% is utterly unsurprising and I bet the 3% are just too new to have had any users in a major breach.

How exactly does that work though? I'm not connived that every name in a data dump indicates a breach at a given company. My thinking: If someone gets a hold of a huge list of usersnaems and passwords from bobcompany.com, and then spams numerous sites with those logins to see if they work elsewhere ... and finds that a few work on joecompany.com then puts out that data.... joecompany.com might have their name listed…

> I'm not connived that every name in a data dump indicates a breach at a given company

It doesn’t, the article is marketing bullshit trying to push an dark web monitoring service.

That’s not to say you’d never be interested in these breaches: if joecompany has employees who reuse or iterate (Summer2020 -> Fall2020) their passwords, a breach at bobcompany that includes joecompany employees could give an attacker their first valid login.

Re: State of Cybersecurity Industry Exposure at Dark Web

#18
Any company that is trying to sell automated dark web scraping is selling snake oil. Many of the 'legit' places to purchase stolen data have vetting procedures before a person is allowed to participate in (or even view) the marketplace.

There are a few companies that have analysts that are in these marketplaces, and they provide actionable intelligence, but they are not cheap.

Re: State of Cybersecurity Industry Exposure at Dark Web

#19

Any company that is trying to sell automated dark web scraping is selling snake oil. Many of the 'legit' places to purchase stolen data have vetting procedures before a person is allowed to participate in (or even view) the marketplace. There are a few companies that have analysts that are in these marketplaces, and they provide actionable intelligence, but they are not cheap.

There are many CIOs at small/medium companies who don't understand any of this and will pay because it makes them feel better.

Re: State of Cybersecurity Industry Exposure at Dark Web

#20
post #13
post #7

While the evidence is light. Is anyone surprised if this is true? My experience is that most cybersecurity firms are only slightly better than other enterprises. They often have lofty standards that they themselves don't follow. They also have professional service arms that are similar to the rest of the industry. Handful of senior people and an army of junior engineers that bias towards velocity over quality (i.e. t…

I know an attorney who was quite capable legally and with tech and spent his career in both. He ended up at a legal organization that also dealt with security. The cybersecurity industry is absolutely full of crappy security companies worth jack squat. The legal industry is full of Luddites. Being capable in both areas = some serious demand / profit.

Yeah I don't really agree. I have both software engineering and law degrees and would love to do something on the nexus tech/law/security but there are very few jobs where deep knowledge of several is a real plus. It's at best an 'oh that's nice' level thing. I'm open to jobs in the south of The Netherlands, eastern Belgium or western Germany if anyone is looking :)
Post reply on HN